security research
iltosec
ILTOSEC
writeups & research

Blog

RSS
1 posts
/
categories
tags
Rce·File Upload Bypass·Command Injection · Rce·File Upload Bypass·misconfiguration
Unauthenticated RCE in CKFinder via Null Byte Injection Vulnerability
A real-world pre-auth RCE chain: exposed CKFinder with no authentication, null byte filter bypass to upload a .cfm webshell, and OS command execution via ColdFusion cfexecute. Full PoC walkthrough.
2026-06-07
24 1 5 min read