PHP 5.4.1 in CGI mode, vulnerable to CVE-2012-1823: php-cgi parses a query string that has no = sign as command-line arguments, so ?-s discloses source and -d allow_url_include=on with -d auto_prepend_file=php://input runs PHP code sent in the body.
Not startedDockercommit 2373ef4x86_64 · aarch64Secret
Exploit CVE-2012-1823 to inject php-cgi options, run commands on the server and get a shell.
The brief for this lab lives in its repository.