Sploitus

Exploit for Improper Encoding or Escaping of Output in F5 Nginx

gitee · 2021-03-29

Exploit Code

MARKDOWN54 lines
## https://sploitus.com/exploit?id=D7EB078F-818F-5F46-A2E2-FC854A8523C7
It is an offensive tool for various areas. The repository contains a collection of vulnerable docker environments, including:

CouchDB
FFmpeg
Git
InfluxDB
Jenkins
Nginx
Oracle Java
Apache HTTP Server
GitLab
FastJSON
Jenkins
Electron

The vulnerabilities include:

CVE-2016-9086 (GitLab)
CVE-2016-10134 (CouchDB)
CVE-2017-2824 (CouchDB)
CVE-2020-11800 (CouchDB)
CVE-2013-4547 (Nginx)
CVE-2017-1000353 (Jenkins)
CVE-2018-1000006 (Electron)
CVE-2016-4547 (Apache HTTP Server)

The probable entry points include:

Docker images
Docker Compose files
Bash scripts

The notable dependencies/tooling include:

Docker
Docker Compose
Bash

The execution context includes:

Docker images
Docker Compose files
Bash scripts

The preconditions include:

Vulnerable versions of the software
Specific configurations

The expected impact includes:

Remote code execution
-