Nginx UI是Jacky个人开发者的一个 Nginx 的 WebUI。 Nginx UI 2.0.0.beta.9之前版本存在SQL注入漏洞,攻击者利用该漏洞可以通过OrderAndPaginate参数来执行SQL 注入 。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-22197 | 7.7 HIGH | Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-202 |
| CVE-2024-22198 | 7.1 HIGH | Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GH |
No comments yet