Nginx 1.4.2 passing *.php to PHP-FPM, with an upload page that refuses PHP extensions, vulnerable to CVE-2013-4547: a request for "shell.gif \0.php" matches the PHP location while Nginx resolves the file "shell.gif ", so an uploaded image runs as PHP.
Pas commencéDockercommit d55115bx86_64 · aarch64Secret
Exploit CVE-2013-4547 to make Nginx run an uploaded file as PHP and get a shell.
Le brief de ce lab se trouve dans son dépôt.