Nuclei template designed to detect Apache servers vulnerable to CVE-2024-38473. It first identifies servers running Apache < 2.4.60 with default PHP-FPM settings.
Then, it fuzzes for potential PHP files protected by ACLs that might be bypassed due to this vulnerability.
git clone https://github.com/juanschallibaum/CVE-2024-38473-Nuclei-Template 2. Navigate to the cloned repository directory:
cd CVE-2024-38473-Nuclei-Template nuclei -t CVE-2024-38473.yaml -u http://example.com nuclei -t CVE-2024-38473.yaml -l hosts.txt nuclei -t CVE-2024-38473.yaml -u http://example.com/valid.php To easily test the CVE-2024-38473 vulnerability, you can set up a vulnerable environment using Docker. Follow these steps to quickly verify the effectiveness of the Nuclei template:
sudo systemctl start docker For more information click here.
The groupdel command in Linux removes a group from the system. It deletes the group's entry from /etc/group and /etc/gshadow,…
The wc command in Linux counts lines, words, characters, and bytes in files or standard input. It…
The top command in Linux provides a real-time view of running processes and system resource usage. From…
The usermod command in Linux modifies existing user account attributes. You can use it to manage group…
The sort command in Linux reads lines from files or standard input and writes them to standard…
The wall command in Linux sends a message to the terminals of all currently logged-in users. The…