nginx passing PHP requests to PHP-FPM 7.2.10 with a fastcgi_split_path_info regex that a newline breaks, vulnerable to CVE-2019-11043: an empty PATH_INFO makes PHP-FPM write past a buffer and rewrite its own environment, until PHP settings such as auto_prepend_file are set.
Pas commencéDockercommit 6a550e5x86_64 · aarch64Secret
Exploit CVE-2019-11043 to run a command on the PHP-FPM server and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.