Sploitus

Exploit for Improper Encoding or Escaping of Output in F5 Nginx

gitee · 2020-07-30

Exploit Code

MARKDOWN2 lines
## https://sploitus.com/exploit?id=A736A729-CAB4-5F61-B608-BBB4D8C1B518
It is an open-source collection of pre-built vulnerable docker environments. The primary CVE ID is not explicitly mentioned, but the repository contains various vulnerable environments, including ones related to CVE-2016-9086, CVE-2017-1000353, CVE-2013-4547, and CVE-2018-1000006. The target product/service or framework is docker, docker-compose, and various web applications (e.g., Flask, Apache, Nginx). The vulnerability class/vector includes SQL injection, remote code execution, and deserialization vulnerabilities. Notable dependencies/tooling include docker, docker-compose, and various programming languages (e.g., Python, Java). The execution context includes CLI usage and HTTP endpoints/methods. The repository provides various vulnerable environments, each with its own README file, which describes the vulnerability and how to exploit it. The environments are designed to be easy to use, with a simple "docker-compose build" command to compile the environment and a "docker-compose up" command to run it.