CCTV - CTF
Mar 12, 2026Leveraging SQL injection in ZoneMinder and MotionEye RCE to compromise a surveillance host
Leveraging SQL injection in ZoneMinder and MotionEye RCE to compromise a surveillance host
Exploiting XSLT injection for arbitrary file write to achieve RCE via cron jobs, followed by priv-esc through a vulnerable needrestart version.
Gaining root access on Data via Grafana LFI and Docker
Chaining an Apache CXF SSRF with a Hoverfly middleware RCE for initial access to exploit a world-writable system binary for root access.
Chaining an unauthenticated MCPJam command execution for initial access to exploit a hidden Python API administrative function for root access.
Chaining NFS credential leaks and password reuse to exploit OpenSTAManager command injection, followed by an OliveTin validation bypass for root access.
Exploiting an exposed Git repository, SQL injection, and dynamic rule execution to obtain root access
Chaining an Apache NiFi H2 Database RCE for initial access to exploit an internal OPC UA service, manipulating PLC safety variables to trigger a conditional sudo privilege escalation for root access.
Chaining an unauthenticated Mirth Connect RCE with database credential recovery for initial access to exploit a Python-based server-side template injection for root access.
Chaining RCE in MCPJam with an LFI-to-RCE pivot in PrivateBin to exploit an internal Docker management service for root access.
Chaining API credential leaks with Cacti command injection, and a Docker api exposure to gain root access.
Bypassing pac4j-jwt authentication with a forged JWE token and exploiting SSH Certificate Authorities for root access
Chaining a React2shell vulnerability for initial access and database credential recovery to exploit a locally exposed Node.js WebSocket debugger for root access.
Chaining an unauthenticated password reset with a Flowise RCE for initial access to exploit a symlink-based vulnerability in an internal Gogs service for root access.
Chaining an MLFlow insecure deserialization vulnerability for initial access to exploit a passwordless sudo script via Python library hijacking for root access.
Exploiting unauthenticated RCE in Wing FTP Server for initial access and abusing an insecure tar archive restore script for root privileges.