References https://www.saury.net/2475.html https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/nginxWebUI-cmdOver-%E5%90%8E%E5%8F%B0%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md https://zhuanlan.zhihu.com/p/640514269 https://cloud.tencent.com/developer/article/2313332 https://stack.chaitin.com/techblog/detail/118 https://developer.aliyun.com/article/1338560 https://cn-sec.com/archives/1859612.html https://www.h3c.com/cn/d_202309/1930895_30003_0.htm https://www.cnvd.org.cn/flaw/show/CNVD-2024-20271 https://www.ddpoc.com/DVB-2024-6875.html
Related VulnerabilitiesPoCNginxWebUI /adminPage/login/getAuth 命令执行漏洞PoCNginxWebUI /Adminpage/Conf/loadOrg 文件读取漏洞NginxWebUI /Api/Nginx/runNginxCmd 命令执行漏洞NginxWebUI /Adminpage/Remote/cmdOver 命令执行漏洞PoCnginxwebui-admin-bypass: NginxWebUI admin认证绕过(全版本通杀)PoCnginxwebui-rce: Nginx Web UI RCEPoCnginx-webui-rce: nginxWebUI ≤ 3.5.0 - Remote Command ExecutionPoCnginxwebui-runcmd-rce: nginxWebUI ≤ 3.5.0 runCmd - Remote Command ExecutionNginxWebUI /adminPage/main/upload 任意文件上传漏洞nginxWebUI 远程代码执行漏洞nginxWebUI getAuth 远程命令执行漏洞nginxWebUI addOver 任意用户创建漏洞nginxWebUI check 远程命令执行漏洞