> From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225)
[AUTHOR: Julien Ahrens]
[DATE: 01/12/2022 15:16]
[LANGUAGE: EN]
Introduction You’ve probably enjoyed my previous post about bypassing Intel DCM’s authentication mechanism to gain unauthorized access. This gave us the lowest possible “Guest” privileges in the DCM console. The second part will now show you a possible way to get Remote Code Execution on the underlying host by exploiting an authenticated SQL Injection vulnerability, […]