Tar Wildcard Injection PrivEsc
Tar command with wildcard injection may lead to privilege escalation (PrivEsc).
sudo -l
(root) NOPASSWD: /opt/backup/baskup.sh
Copied!cat /opt/backup/backup.sh
# -cf: create an archived file
tar -cf backup.tar *
Copied!Last updated
