security research
iltosec
ILTOSEC
writeups & research

Blog

RSS
7 posts
/
categories
tags
Rce·File Upload Bypass·Command Injection · Rce·misconfiguration·File Upload Bypass
Unauthenticated RCE in CKFinder via Null Byte Injection Vulnerability
A real-world pre-auth RCE chain: exposed CKFinder with no authentication, null byte filter bypass to upload a .cfm webshell, and OS command execution via ColdFusion cfexecute. Full PoC walkthrough.
2026-06-07
24 1 5 min read
Rce·CVE · Rce
FacturaScripts <= 2026 Authenticated RCE via Malicious Plugin Upload
Detailed vulnerability analysis of an Authenticated Remote Code Execution (RCE) in FacturaScripts (<= 2026). Explore the PoC via malicious plugin upload and learn about server hardening mitigations.
2026-05-01
215 2 3 min read
Rce·File Upload Bypass·Command Injection · Rce·CMS·File Upload Bypass
EspoCRM v9.3.4 Authenticated Remote Code Execution via Malicious Extension Upload
Explore the technical analysis of the Authenticated Remote Code Execution (RCE) vulnerability in EspoCRM <= v9.3.4. Learn how malicious extension uploads can lead to full OS command execution and find mitigation strategies. Official PoC and exploit details included.
2026-04-13
293 1 3 min read
Rce·CVE · Rce·CMS
.NET Deserialization Leading to Remote Code Execution (CVE-2019-18211)
This blog post explains the black-box exploitation of Composite C1 CMS via CVE-2019-18211. The deserialization vulnerability in the EntityTokenSerializer class allows attackers to achieve remote code execution (RCE) on the server. Step-by-step attack and mitigation recommendations are provided.
2025-08-15
1058 12 3 min read
SSTI·Rce·Command Injection · Rce
Whitebox Web Pentesting: Exploiting Flask Authentication & RCE in Chain Lab
A detailed walkthrough of **Chain Lab** from **CyberExam.io**, demonstrating a Flask web app's **authentication bypass**, **SQL injection**, **hash cracking**, and **RCE exploitation**. Learn how to chain web vulnerabilities for real-world penetration testing.
2025-05-06
1337 9 2 min read
Rce·File Upload Bypass·Authentication Bypass · Rce·File Upload Bypass
Exploiting Flask Authentication and RCE Vulnerabilities – Chain Lab Writeup
Learn how to exploit Flask authentication and remote code execution (RCE) vulnerabilities in the Chain Lab challenge on CyberExam. This step-by-step writeup demonstrates bypassing Flask session authentication, uploading a reverse shell payload, and gaining full control over the system.
2024-12-02
8467 11 4 min read
Rce · Rce
Remote Code Execution by Bypassing Cloudflare: CVE-2022–29464 Analysis
Explore the detection and exploitation of CVE-2022-29464, a critical vulnerability in WSO2 products that allows remote code execution. Learn how to bypass Cloudflare's security and achieve shell access with a custom web shell. This article provides a detailed step-by-step guide, highlighting important lessons in web application security and the need for constant testing and updating of defense mechanisms.
2024-11-11
1867 7 8 min read