Apache HTTP Server 2.4.10 with mod_php and an upload page that blocks .php names, vulnerable to CVE-2017-15715: the $ in the FilesMatch regular expression also matches before a trailing newline, so a file named evil.php followed by \x0a is stored and then executed as PHP.
Not startedDockercommit ad8acc4x86_64 · aarch64Secret
Exploit CVE-2017-15715 to upload a PHP file past the extension filter and run commands on the server.
The brief for this lab lives in its repository.