Nginxui

Nginx Ui

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.52%
  • Veröffentlicht 21.10.2024 17:15:03
  • Zuletzt bearbeitet 07.11.2024 15:15:04

Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the ser...

  • EPSS 0.43%
  • Veröffentlicht 21.10.2024 17:15:03
  • Zuletzt bearbeitet 07.11.2024 14:57:17

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the...

Exploit
  • EPSS 67.53%
  • Veröffentlicht 21.10.2024 17:15:03
  • Zuletzt bearbeitet 06.11.2024 18:28:54

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-bet...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 13.04.2024 18:15:07
  • Zuletzt bearbeitet 21.08.2025 00:52:54

A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation of the argument nginxPath leads to improper certificate validation. It...

  • EPSS 1.38%
  • Veröffentlicht 29.01.2024 17:15:10
  • Zuletzt bearbeitet 21.11.2024 08:58:30

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix f...

  • EPSS 2.97%
  • Veröffentlicht 29.01.2024 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:58:30

Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths i...

Exploit
  • EPSS 20.31%
  • Veröffentlicht 11.01.2024 20:15:45
  • Zuletzt bearbeitet 21.11.2024 08:55:46

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node ...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 11.01.2024 20:15:44
  • Zuletzt bearbeitet 21.11.2024 08:55:46

Nginx-UI is an online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"` and `"id"` values are used as de...

Exploit
  • EPSS 4.24%
  • Veröffentlicht 11.01.2024 18:15:45
  • Zuletzt bearbeitet 21.11.2024 08:55:46

Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access Log Path` and `Nginx Error Log...