This is a detailed technical writeup describing multiple vulnerabilities in Kloxo/Lxadmin, including UID/GID reuse, unprivileged port use, default passwords, XSS, and directory traversal. It provides specific attack vectors and proof-of-concept steps but does not include functional exploit code.
Classification
Writeup 100%
Target:
Kloxo/Lxadmin (HostInaBox 5.7.5)
No auth needed
Prerequisites:
Access to Kloxo/Lxadmin interface · Local or remote access depending on the issue