Sploitus

Exploit for Improper Encoding or Escaping of Output in F5 Nginx

gitee · 2021-08-15

Exploit Code

MARKDOWN18 lines
## https://sploitus.com/exploit?id=FF5FDC41-A333-5EAB-9A5C-05C88F66687E
This is an open-source collection of vulnerable web applications and environments for security testing and education. The repository is maintained by phith0n and is available on GitHub. It contains a variety of vulnerable applications, including web servers, databases, and other systems, to help users learn about common web application vulnerabilities and how to exploit them.

The repository includes a range of applications, such as:

CouchDB: A NoSQL database with a known vulnerability (CVE-2016-9086)
FFmpeg: A multimedia processing application with known vulnerabilities (CVE-2018-1000006)
Git: A version control system with known vulnerabilities (CVE-2016-10099)
Jenkins: A continuous integration and deployment tool with known vulnerabilities (CVE-2017-1000353)
Nginx: A web server with known vulnerabilities (CVE-2013-4547)
Oracle Java: A programming language with known vulnerabilities (CVE-2017-3454)
Apache HTTP Server: A web server with known vulnerabilities (CVE-2017-1000117)

The repository also includes a range of tools and scripts to help users test and exploit these vulnerabilities, such as:

Exploit modules for Metasploit
Burp Suite extensions
Nmap