<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>dgovalen</title><description>Security researcher — CVEs, HTB writeups, research.</description><link>https://dgovalen.cl/</link><item><title>CVE-2026-54053 — Path Traversal + Stored XSS vía Importación ZIP en Many Notes</title><link>https://dgovalen.cl/cves/cve-2026-54053/</link><guid isPermaLink="true">https://dgovalen.cl/cves/cve-2026-54053/</guid><description>ZIP import sin sanitización de path traversal + validación MIME permisiva en brufdev/many-notes permite escritura arbitraria entre vaults y XSS almacenado. CVSS 9.6 Crítico.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Full TTY en Linux</title><link>https://dgovalen.cl/blog/full-tty/</link><guid isPermaLink="true">https://dgovalen.cl/blog/full-tty/</guid><description>Cómo obtener una Full TTY desde una reverse shell para tener autocompletado, Ctrl+C, y moverse cómodamente por el sistema.</description><pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate></item><item><title>CozyHosting</title><link>https://dgovalen.cl/htb/cozyhosting/</link><guid isPermaLink="true">https://dgovalen.cl/htb/cozyhosting/</guid><description>Spring Boot actuator expone session tokens → command injection en SSH config → credenciales en JAR → escalada con sudo ssh.</description><pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate></item><item><title>Inject</title><link>https://dgovalen.cl/htb/inject/</link><guid isPermaLink="true">https://dgovalen.cl/htb/inject/</guid><description>Path traversal en image viewer expone credenciales → Spring RCE (CVE-2022-22963) → escalada con Ansible playbook malicioso ejecutado por cron root.</description><pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate></item><item><title>Love</title><link>https://dgovalen.cl/htb/love/</link><guid isPermaLink="true">https://dgovalen.cl/htb/love/</guid><description>UNION-based SQLi en voting system Windows → file upload PHP shell → AlwaysInstallElevated para escalar a SYSTEM con MSI malicioso.</description><pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate></item><item><title>Timelapse</title><link>https://dgovalen.cl/htb/timelapse/</link><guid isPermaLink="true">https://dgovalen.cl/htb/timelapse/</guid><description>SMB anónimo expone ZIP protegido → fuerza bruta ZIP y PFX → Evil-WinRM con certificado → historial PowerShell → LAPS_Readers extrae password de Administrator.</description><pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate></item></channel></rss>