Nginx UI是Jacky个人开发者的一个 Nginx 的 WebUI。 Nginx UI 2.0.0.beta.9之前版本存在命令注入漏洞,攻击者利用该漏洞可以通过修改 start_cmd设置来执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Identify Nginx-ui version and check if it's vulnerable to CVE-2024-22198 | https://github.com/xiw1ll/CVE-2024-22198_Checker | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-22197 | 7.7 HIGH | Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-202 |
| CVE-2024-22196 | 7.0 HIGH | Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270) |
No comments yet