Sploitus

Exploit for Improper Encoding or Escaping of Output in F5 Nginx

gitee · 2021-09-26

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=A493343D-B50C-5C6F-8F34-3844AA4D6263
This is an offensive tool for web application security training. It is a collection of vulnerable web applications, each with its own set of vulnerabilities, designed to help users learn and practice web application security testing.

The repository contains a variety of web applications, including:

CouchDB
FFmpeg
Git
Jenkins
Jenkins (with a vulnerability in the Jenkins WAR file)
Nginx
Oracle Java
Apache HTTP Server
GitLab
FastJSON
Electron

Each application has its own set of vulnerabilities, which are listed in the `.gitattributes` file. The vulnerabilities include:

CVE-2016-10134 (CouchDB)
CVE-2017-2824 (CouchDB)
CVE-2020-11800 (CouchDB)
CVE-2013-4547 (Nginx)
CVE-2016-9086 (GitLab)
CVE-2017-1000353 (Jenkins)
CVE-2018-1000006 (Electron)
CVE-2016-9086 (GitLab)
CVE-2017-1000353 (Jenkins)
CVE-2018-1000006 (Electron)

The repository also contains workflows for