grep -l "LFI" ./machines (3)

VariaType [Linux]
Medium
Exploited fonttools CVE-2025-66034 designspace path traversal to write a PHP webshell, escalated to user via FontForge archive command injection, then root via setuptools PackageIndex arbitrary file write to cron.d.
fonttoolsCVE-2025-66034path-traversalPHP-injectionLFIgit-exposure +5
● pwned
Pterodactyl [Linux]
Medium
Unauthenticated RCE via Pterodactyl Panel LFI (CVE-2025-49132), credential reuse for SSH, then privilege escalation via PAM session injection (CVE-2025-6018) chained with udisks2 XFS resize race condition (CVE-2025-6019) to obtain root.
CVE-2025-49132LFIpearcmdRCECVE-2025-6018CVE-2025-6019 +6
● pwned
Facts [Linux]
Easy
Exploited CamaleonCMS path traversal (CVE-2024-46987) to extract MinIO credentials and an encrypted SSH key, then escalated via sudo facter --custom-dir to root.
CamaleonCMSCVE-2024-46987LFIMinIOSSH Key CrackingFacter Sudo Abuse
● pwned