2 Videos for CVE-2020-8163: Rails local name RCE

PRO
Tier
difficulty_hard_icon
Hard
clock icon
1-2 Hrs.
number of users completed icon
219
badge icon
Brown Badge
image of exercise CVE-2020-8163: Introduction
play btn
Access to videos for this exercise is only available with PentesterLab PRO GOPRO
CVE-2020-8163: Introduction

In this video, we delve into CVE-2020-8163, a vulnerability impacting specific Ruby-on-Rails applications with a particular code pattern. We explore how to identify and exploit this vulnerability, emphasizing the importance of understanding partial views in Ruby.

video duration icon05:39 number of views icon399

 

image of exercise CVE-2020-8163: Exploitation
play btn
Access to videos for this exercise is only available with PentesterLab PRO GOPRO
Spoiler
CVE-2020-8163: Exploitation

In this video, we cover the exploitation of CVE-2020-8163 as part of the Brown Badge series. We demonstrate how to leverage a parameter name injection to achieve code execution by using specific Ruby commands.

video duration icon04:45 number of views icon411