/ tags
#sqli
2 writeups tagged sqli.
CCTV easy featured
Default credentials on an exposed ZoneMinder console lead to a blind SQL injection (CVE-2024-51482) that dumps a crackable hash for SSH. Root comes from a loopback-bound motionEye reached over an SSH tunnel, where a filename field is passed unsanitised to a Motion daemon running as root (CVE-2025-60787).
linuxwebzonemindersqliCVE-2024-51482motioneyeCVE-2025-60787ssh-tunnelingcommand-injection
07 Mar 2026
HTB
Gavel medium
Linux web box: exposed .git repo leaks PHP source revealing a SQLi, admin panel RCE via PHP rule engine, then privesc by abusing a root-run auction daemon that executes YAML-defined PHP rules.
linuxwebsqligit-dumperphprceyamlsuidprivesc
12 Oct 2025
HTB