← back to room
RCE

StockPulse — Blog comments

Scenario

Blog comments are saved to disk and later included when posts are viewed. Your comment text becomes part of a server-side include path. Leave a comment that executes system commands when an admin opens the post.

Your approach

  1. Post a normal comment and confirm it appears on the blog view.
  2. Submit a comment containing server-side code that runs id or similar.
  3. Open the post view to trigger inclusion of your file.
  4. Read the uid line for www-data from the output.
  5. Submit the exact uid string shown in the lab.
Internal blog

Leave a comment

Comments persist and are rendered when you open them individually.

Comments

No comments yet.