<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>File-Upload :: X3ric Blog</title><link>https://x3ric.com/blog/tags/file-upload/</link><description>CTF notes, systems work, and writeups.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 06 Jun 2026 21:41:13 +0200</lastBuildDate><atom:link href="https://x3ric.com/blog/tags/file-upload/index.xml" rel="self" type="application/rss+xml"/><item><title>HackTheBox CachedWeb Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-CachedWeb-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-CachedWeb-Challenge/</guid><pubDate>Tue, 23 Sep 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>ssrf</category><category>path-traversal</category><category>file-upload</category><category>rce</category><category>flask</category><description>CachedWeb: chain SSRF with path control to reach the internal target and read the flag.</description></item><item><title>HackTheBox DoxPit Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-DoxPit-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-DoxPit-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>template-injection</category><category>ssrf</category><category>file-upload</category><category>flask</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox PetPet Rcbee Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-PetPet-Rcbee-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-PetPet-Rcbee-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>file-upload</category><description>PetPet Rcbee: abuse file-upload to cross the web trust boundary and recover the flag.</description></item><item><title>HackTheBox Prying Eyes Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Prying-Eyes-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Prying-Eyes-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>path-traversal</category><category>file-upload</category><description>Prying Eyes: use path traversal to escape the intended read path and recover the flag.</description></item></channel></rss>