2 Videos for DOMPDF RCE

PRO
Tier
Medium
Medium
156 completed
Return to Exercise
image of exercise DOMPDF RCE: Introduction

This video requires PentesterLab PRO

GO PRO
DOMPDF RCE: Introduction

In this video, we explore an introduction to the DOMPDF RCE challenge, part of the media badge on PentesterLab. We discuss how attackers can exploit the DOMPDF library to execute remote code by injecting malicious HTML and CSS to create a web shell.

video duration icon05:12 number of views icon216

 

image of exercise DOMPDF RCE: Exploitation

This video requires PentesterLab PRO

GO PRO
Spoiler
DOMPDF RCE: Exploitation

In this video, we cover the DOMPDF RCE challenge as part of the media badge. We demonstrate how to exploit a Remote Code Execution (RCE) vulnerability in the DOMPDF library by crafting a malicious font file and using it to execute arbitrary PHP code on the server.

video duration icon06:02 number of views icon309