Media Badge
22 Videos
18 Exercises
The media badge is our set of exercises created to teach you how to abuse applications that allows you to upload or retrieve files in different formats: PDF, Images, Videos and use this behaviour to gain code execution or arbitrary file read
Exercises
Easy
PENTESTERLAB
SSRF in PDF generation
- This exercise covers how you can read arbitrary files when an application generates pdfs from provided links
- 1 video
- Completed by 836 students
- Takes < 1 Hr. on average
Coming soon
Easy
PENTESTERLAB
ODF XXE
- This exercise covers the exploitation of an XXE in an ODF Parser
- Takes -- on average
Medium
PENTESTERLAB
CVE-2022-39224
- This exercise covers the exploitation of CVE-2022-39224
- 1 video
- Completed by 81 students
- Takes 2-4 Hrs. on average
- Ruby
- CWE-78
Medium
PENTESTERLAB
XSL PHP
- This exercise covers the exploitation of a PHP application using XSL
- 2 videos
- Completed by 250 students
- Takes < 1 Hr. on average
- PHP
- CWE-94,CWE-306
Medium
PENTESTERLAB
XSL PHP II
- This exercise covers the exploitation of a PHP application using XSL
- 2 videos
- Completed by 214 students
- Takes < 1 Hr. on average
- PHP
- CWE-94
Medium
PENTESTERLAB
DOMPDF RCE
- This exercise covers the exploitation of a vulnerability in the DOMPDF library
- 2 videos
- Completed by 130 students
- Takes < 1 Hr. on average
- PHP
Medium
PENTESTERLAB
XSL PHP IV
- This exercise covers the exploitation of a PHP application using XSL
- 2 videos
- Completed by 129 students
- Takes 2-4 Hrs. on average
- PHP
- CWE-94
Medium
PENTESTERLAB
DOMPDF RCE III
- This exercise covers the exploitation of a vulnerability in the DOMPDF library
- 2 videos
- Completed by 45 students
- Takes 2-4 Hrs. on average
- PHP
Medium
PENTESTERLAB
XSL Java
- This exercise covers the exploitation of a Java application using XSL
- 2 videos
- Completed by 101 students
- Takes < 1 Hr. on average
- Java
Medium
PENTESTERLAB
DOMPDF RCE II
- This exercise covers the exploitation of a vulnerability in the DOMPDF library
- 3 videos
- Completed by 60 students
- Takes 2-4 Hrs. on average
- PHP
Medium
PENTESTERLAB
XSL PHP III
- This exercise covers the exploitation of a PHP application using XSL
- 2 videos
- Completed by 152 students
- Takes < 1 Hr. on average
- PHP
- CWE-94
Hard
PENTESTERLAB
XSL PHP V
- This exercise covers the exploitation of a PHP application using XSL
- 2 videos
- Completed by 97 students
- Takes < 1 Hr. on average
- PHP
- CWE-94
Hard
PENTESTERLAB
CVE-2021-22204: Exiftool RCE
- This exercise covers how you can gain code execution when an application uses exiftool on user-controlled files
- 1 video
- Completed by 163 students
- Takes 1-2 Hrs. on average
- CWE-74