
Pwned Nibbles on HTB CVE-2015-6967 → uploaded a PHP reverse shell via Nibbleblog's My Image plugin → caught shell as nibbler → abused misconfigured sudo on http://monitor.sh → root 🏆 https://labs.hackthebox.com/achievement/machine/3216229/121 #HackTheBoxOndo #HTB #CyberSecurity #EthicalHacking #InfoSec
Post summary
A HackTheBox participant exploited CVE‑2015‑6967 by uploading a PHP reverse shell through Nibbleblog's My Image plugin and abusing a misconfigured sudo to gain root, demonstrating a working exploit scenario.


