Nginx UI是Jacky个人开发者的一个 Nginx 的 WebUI。 Nginx UI 2.0.0-beta.36之前版本存在安全漏洞,该漏洞源于其日志路径是可控的,导致攻击者可以结合/api/configs处的目录遍历来读取服务器上的目录和文件内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-49366 | Nginx UI's json field can construct a directory traversal payload, causing arbitrary files | |
| CVE-2024-49368 | Unchecked logrotate settings lead to arbitrary command execution |
No comments yet