Media Badge

The media badge is our set of exercises created to teach you how to abuse applications that allows you to upload or retrieve files in different formats: PDF, Images, Videos and use this behaviour to gain code execution or arbitrary file read

22 exercises 22 videos

Exercises

Coming soon
Easy
Media Badge badge icon
ODF XXE
  • This exercise covers the exploitation of an XXE in an ODF Parser
  • PHP
  • CWE-611

Easy
Media Badge badge icon
SSRF in PDF generation
  • This exercise covers how you can read arbitrary files when an application generates pdfs from provided links
  • 1 video
  • Completed by 939 students
  • Takes < 1 Hr. on average

Coming soon
Medium
Media Badge badge icon
CVE-2026-55415: Schema Import Injection
  • Gain code execution by injecting Python through a crafted JSON Schema when the generated Pydantic model is imported.
  • Python
  • CWE-94

Medium
Media Badge badge icon
Latex: --shell-escape
  • This exercise covers how one can leverage latex when pdflatex is used with the --shell-escape option to gain command execution.
  • Completed by 65 students
  • Takes < 1 Hr. on average
  • Ruby/Latex

Medium
Media Badge badge icon
CVE-2022-24720
  • This exercise covers how one can leverage image processing in ActiveStorage to gain command execution.
  • Completed by 47 students
  • Takes 1-2 Hrs. on average
  • Ruby/Rails

Medium
Media Badge badge icon
CVE-2022-39224
  • This exercise covers the exploitation of CVE-2022-39224
  • 1 video
  • Completed by 117 students
  • Takes < 1 Hr. on average
  • Ruby
  • CWE-78

Medium
Media Badge badge icon
DOMPDF RCE
  • This exercise covers the exploitation of a vulnerability in the DOMPDF library
  • 2 videos
  • Completed by 169 students
  • Takes < 1 Hr. on average
  • PHP

Medium
Media Badge badge icon
XSL PHP II
  • This exercise covers the exploitation of a PHP application using XSL
  • 2 videos
  • Completed by 256 students
  • Takes < 1 Hr. on average
  • PHP
  • CWE-94

Medium
Media Badge badge icon
XSL PHP
  • This exercise covers the exploitation of a PHP application using XSL
  • 2 videos
  • Completed by 301 students
  • Takes < 1 Hr. on average
  • PHP
  • CWE-94,CWE-306

Coming soon
Medium
Media Badge badge icon
SOAPBridge: Savon WSDL Code Injection
  • Gain code execution through an unsafe module_eval call during WSDL import.
  • Ruby
  • CWE-94

Medium
Media Badge badge icon
CVE-2021-33564 Argument Injection in Ruby Dragonfly
  • This exercise covers how you can get arbitrary file read using CVE-2021-33564 against Refinery CMS
  • Completed by 160 students
  • Takes < 1 Hr. on average
  • CWE-88

Medium
Media Badge badge icon
CVE-2021-22204: Exiftool RCE II
  • This exercise covers how you can gain code execution when an application uses exiftool on user-controlled files
  • Completed by 92 students
  • Takes < 1 Hr. on average
  • CWE-94,CWE-74

Medium
Media Badge badge icon
XSL PHP III
  • This exercise covers the exploitation of a PHP application using XSL
  • 2 videos
  • Completed by 188 students
  • Takes < 1 Hr. on average
  • PHP
  • CWE-94

Medium
Media Badge badge icon
XSL PHP IV
  • This exercise covers the exploitation of a PHP application using XSL
  • 2 videos
  • Completed by 167 students
  • Takes < 1 Hr. on average
  • PHP
  • CWE-94

Medium
Media Badge badge icon
DOMPDF RCE II
  • This exercise covers the exploitation of a vulnerability in the DOMPDF library
  • 3 videos
  • Completed by 82 students
  • Takes < 1 Hr. on average
  • PHP

Medium
Media Badge badge icon
SSRF via FFMPEG
  • This exercise covers how you can read arbitrary files when an application uses ffmpeg to render videos from a video you provide
  • Completed by 263 students
  • Takes < 1 Hr. on average
  • Ruby/FFMpeg
  • CWE-918

Medium
Media Badge badge icon
XSL Java
  • This exercise covers the exploitation of a Java application using XSL
  • 2 videos
  • Completed by 140 students
  • Takes < 1 Hr. on average
  • Java

Medium
Media Badge badge icon
DOMPDF RCE III
  • This exercise covers the exploitation of a vulnerability in the DOMPDF library
  • 2 videos
  • Completed by 66 students
  • Takes < 1 Hr. on average
  • PHP

Hard
Media Badge badge icon
CVE-2021-22204: Exiftool RCE
  • This exercise covers how you can gain code execution when an application uses exiftool on user-controlled files
  • 1 video
  • Completed by 187 students
  • Takes < 1 Hr. on average
  • CWE-74

Hard
Media Badge badge icon
XSL PHP V
  • This exercise covers the exploitation of a PHP application using XSL
  • 2 videos
  • Completed by 132 students
  • Takes < 1 Hr. on average
  • PHP
  • CWE-94

Hard
Media Badge badge icon
SSRF via FFMPEG II
  • This exercise covers how you can read arbitrary files when an application uses ffmpeg to render videos from a video you provide
  • Completed by 138 students
  • Takes < 1 Hr. on average
  • Ruby/FFMpeg
  • CWE-918

Hard
Media Badge badge icon
DOMPDF RCE IV
  • This exercise covers the automation of the exploitation of a vulnerability in the DOMPDF library
  • Completed by 36 students
  • Takes 1-2 Hrs. on average
  • PHP