2 Videos for Gogs RCE II

PRO
Tier
difficulty_hard_icon
Hard
clock icon
< 1 Hr.
number of users completed icon
593
badge icon
Green Badge
image of exercise CVE-2018-20303 - Introduction
play btn
Access to videos for this exercise is only available with PentesterLab PRO GOPRO
CVE-2018-20303 - Introduction

This video covers the CVE-2018-20303 vulnerability exercise from the green badge series. It explains how session management in Gogs can be exploited using directory traversal to create a malicious session file, granting admin access.

video duration icon06:11 number of views icon613

 

image of exercise CVE-2018-20303: Exploitation
play btn
Access to videos for this exercise is only available with PentesterLab PRO GOPRO
Spoiler
CVE-2018-20303: Exploitation

In this video, we dive into the exploitation of CVE-2018-20303 using the Gogs application. We demonstrate how to manipulate session files to gain administrative access and execute arbitrary commands on the server.

video duration icon06:39 number of views icon947