Nginx UI是Jacky个人开发者的一个 Nginx 的 WebUI。 Nginx UI 2.0.0-beta.36之前版本存在输入验证错误漏洞,该漏洞源于配置logrotate时,未验证输入,导致任意命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Explorations of CVE-2024-49368 + Exploit Development | https://github.com/Aashay221999/CVE-2024-49368 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-49366 | Nginx UI's json field can construct a directory traversal payload, causing arbitrary files | |
| CVE-2024-49367 | Nginx UI's log path can be controlled |
No comments yet