Sploitus

Exploit for Integer Overflow or Wraparound in F5 Nginx

githubexploit · 2019-06-06

Exploit Code

README8 lines
## https://sploitus.com/exploit?id=CE44F958-B72B-56FA-B97D-D6911A102D38
# CVE-2017-7529-POC  
**Affected Vulnerabilities**  
This vulnerability affects Nginx modules with default configurations in versions 0.5.6 to 1.13.2. An attacker can send malicious requests via caching to carry out remote attacks and cause information leakage. When Nginx servers use proxy caching, attackers can exploit this vulnerability to obtain the real IP address of the server or other sensitive information. Our analysis indicates that this vulnerability is easy to exploit and can be considered a “low-hanging fruit.” It also has some practical value in real-world attacks.  
**Affected Versions**  
Nginx versions 0.5.6 to 1.13.2  
**Patched Versions**  
Nginx versions 1.13.3, 1.12.1