This website requires JavaScript.
Explore
Help
Sign In
whx
/
killchain-compendium
Watch
1
Star
0
Fork
You've already forked killchain-compendium
0
Code
Issues
Pull Requests
Projects
Releases
Wiki
Activity
9737bfd50d
Branches
Tags
No results found.
killchain-compendium
/
Exploits
/
Ruby
/
yaml_load.md
238 B
Raw
Blame
History
YAML.load deserialization
RCE is is possible via YAML file deserialization through
yaml.load()
.
staadraad describes how and provides a payload