Pinned
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! blog.orange.tw/2024/08/confusβ¦
Highlights include:
β‘ Escaping from DocumentRoot to System Root
β‘ Bypassing built-in ACL/Auth with just a '?'
β‘ Turning XSS into RCE with legacy code
