← back to room
RCE
StockPulse — Blog comments
Scenario
Blog comments are saved to disk and later included when posts are viewed. Your comment text becomes part of a server-side include path. Leave a comment that executes system commands when an admin opens the post.
Your approach
- Post a normal comment and confirm it appears on the blog view.
- Submit a comment containing server-side code that runs id or similar.
- Open the post view to trigger inclusion of your file.
- Read the uid line for www-data from the output.
- Submit the exact uid string shown in the lab.
StockPulse
Internal blog
Leave a comment
Comments persist and are rendered when you open them individually.
Comments
No comments yet.