Blast From The Past

Description

You have been tasked with auditing a legacy system at DDA. This system is said to be so old, it has not been updated since 2014! It is said that it is vulnerable to a very famous vulnerability... Can you exploit it and read the flag at /etc/flag.txt?

Solution

Blast From The Past.png

Website is not showing any routes that go to other pages.

So the only information we have is Apache version 2.4.7; After too much research CVE's led to Shellshock (CVE-2014-6271arrow-up-right)

Checking for common files we get /cgi-bin/test.cgi

circle-check

Last updated