HackTheBox Easy Linux

Conversor

An unsanitized XSLT parser allows arbitrary file writes for RCE. Credentials are recovered from a SQLite database. A Perl config injection grants a root shell.

#Linux#Easy#FTP#SQLite#XSLT-Injection#Linpeas#Hash-Identifier#Hashcat#needrestart#Perl
HackTheBox Easy Linux

WingData

A null-byte injection CVE-2025-47812. Credentials for a second user are recovered from config files. A symlink and hardlink chaining technique CVE-2025-4517.

#Linux#Easy#Python#FTP#Injection#CVE-2025-47812#CVE-2025-4517#Hash-Identifier#Hashcat