grep -l "Command Injection" ./machines (2)

VariaType [Linux]
Medium
Exploited fonttools CVE-2025-66034 designspace path traversal to write a PHP webshell, escalated to user via FontForge archive command injection, then root via setuptools PackageIndex arbitrary file write to cron.d.
fonttoolsCVE-2025-66034path-traversalPHP-injectionLFIgit-exposure +5
โ— pwned
Overwatch [Windows]
Medium
Windows AD DC with anonymous SMB share leaking .NET app credentials, MSSQL linked server DNS poisoning for credential capture, and WCF SOAP service command injection for SYSTEM access.
Active DirectoryMSSQLWCFCommand InjectionDNS PoisoningLinked Server +1
โ— pwned