Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2022-41741 PoC — NGINX ngx_http_mp4_module vulnerability CVE-2022-41741

Source
Associated Vulnerability
Title:NGINX ngx_http_mp4_module vulnerability CVE-2022-41741 (CVE-2022-41741)
Description:NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Description
CVE-2022-41741/742 Nginx Vulnerability Scanner
Readme
# 🛡️ Nginx Vulnerability Scanner
Desarrollado por **m10sec**.

Este script detecta automáticamente la versión de Nginx en un servidor remoto y evalúa si es vulnerable a fallos de seguridad conocidos, específicamente:

- **CVE-2023-44487** – HTTP/2 Rapid Reset Attack
- **CVE-2022-41741** – Corrupción de memoria en `ngx_http_mp4_module`
- **CVE-2022-41742** – Revelación de memoria en `ngx_http_mp4_module`

---

## 🚀 Características

- Solicita al usuario una URL o IP del servidor a analizar.
- Detecta si el servidor está usando Nginx y extrae su versión.
- Verifica si está activo el módulo `ngx_http_mp4_module`.
- Determina si el servidor puede ser vulnerable a las CVEs mencionadas.
- Informa recomendaciones de mitigación si aplica.

---

## 📥 Requisitos

- Python 3.6+
- Librerías:
  ```bash
  pip install requests packaging
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →