A detailed walkthrough of the HackTheBox machine 'Giveback', covering exploitation of CVE-2024-5932, an unauthenticated PHP object injection to RCE vulnerability in the GiveWP WordPress plugin. After gaining a shell in a Kubernetes pod, the attacker enumerates the cluster environment, discovers a legacy internal PHP-CGI
Table of contents
Box InfoReconShell in WordPress K8 PodShell as root on legacy-internet-cms PodShell as babywyrmShell as rootSort: