Course
In this challenge, participants will explore how to exploit DOMPDF 2.0.1 to achieve remote code execution (RCE) by leveraging a vulnerability in its SVG parsing. This practical lab involves crafting a malicious font file and exploiting an HTML injection to gain code execution on the server.
Skills covered
Ready to practice?
Get access to this lab and 600+ hands-on exercises with a PRO subscription.