0xleft

1 exploit Active since Jan 2020
CVE-2019-20372 NOMISEC MEDIUM WORKING POC
NGINX < 1.17.7 - HTTP Request Smuggling via error_page Configuration
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
5 stars
CVSS 5.3