DOMPDF RCE: Exploitation

image of exercise DOMPDF RCE: Exploitation
Access to videos for this exercise is only available with PentesterLab PRO GOPRO
Spoiler
DOMPDF RCE: Exploitation

In this video, we cover the DOMPDF RCE challenge as part of the media badge. We demonstrate how to exploit a Remote Code Execution (RCE) vulnerability in the DOMPDF library by crafting a malicious font file and using it to execute arbitrary PHP code on the server.

video duration icon06:02 number of views icon249