nginx passing PHP requests to PHP-FPM 7.2.10 with a fastcgi_split_path_info regex that a newline breaks, vulnerable to CVE-2019-11043: an empty PATH_INFO makes PHP-FPM write past a buffer and rewrite its own environment, until PHP settings such as auto_prepend_file are set.
Not startedDockercommit 515bc43x86_64 · aarch64Secret
Exploit CVE-2019-11043 to run a command on the PHP-FPM server.
The brief for this lab lives in its repository.