$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PHP knowledge base platform (KnowledgeForge v2.4.1, based on phpMyFAQ) behind nginx reverse proxy with restrictive location matching that blocks direct access to all routes. Solution: Bypassed nginx routing via double-slash prefix (//index.php/), then exploited CVE-2024-28105 by injecting .php into the lang parameter of category image upload with a GIF polyglot webshell, achieving RCE as root.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar