Nuclei template designed to detect Apache servers vulnerable to CVE-2024-38473. It first identifies servers running Apache < 2.4.60 with default PHP-FPM settings.
Then, it fuzzes for potential PHP files protected by ACLs that might be bypassed due to this vulnerability.
git clone https://github.com/juanschallibaum/CVE-2024-38473-Nuclei-Template
2. Navigate to the cloned repository directory:
cd CVE-2024-38473-Nuclei-Template
nuclei -t CVE-2024-38473.yaml -u http://example.com
nuclei -t CVE-2024-38473.yaml -l hosts.txt
nuclei -t CVE-2024-38473.yaml -u http://example.com/valid.php
To easily test the CVE-2024-38473 vulnerability, you can set up a vulnerable environment using Docker. Follow these steps to quickly verify the effectiveness of the Nuclei template:
sudo systemctl start docker
For more information click here.
garak checks if an LLM can be made to fail in a way we don't…
Vermilion is a simple and lightweight CLI tool designed for rapid collection, and optional exfiltration…
ADCFFS is a PowerShell script that can be used to exploit the AD CS container…
Tartufo will, by default, scan the entire history of a git repository for any text…
Loco is strongly inspired by Rails. If you know Rails and Rust, you'll feel at…
A data hoarder’s dream come true: bundle any web page into a single HTML file.…