Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-11043 — Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix) | Kitploit
Tools/GitHubGitHub/k8gege/cve-2019-11043
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubk8gege/cve-2019-11043

CVE-2019-11043

Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)

View Repository
16136 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)

Vulnerability Overview

PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043)

During the Real World CTF organized by Chaitin Tech, foreign security researcher Andrew Danau discovered while solving a CTF challenge that sending the %0a symbol to the target server URL caused abnormal responses, suggesting a vulnerability.

With some misconfigured Nginx setups, a maliciously crafted packet can cause PHP-FPM to execute arbitrary code.

Example

Place it in the same directory as Ladon.exe to perform batch detection on a C-class subnet or url.txt.

root@kitploit:~
Ladon CVE-2019-11043_Poc.ini 批量URL检测(根目录下放url.txt)
Ladon 192.168.1.37/24 CVE-2019-11043_Poc.ini 批量检测C段主机是否存在该漏洞
Ladon http://192.168.1.37:8080/index.php CVE-2019-11043_Poc.ini 指定URL
Ladon 5.5
By K8gege
Call AnyExe/Command
http://192.168.1.37:8080/index.php
load F:\Python279\python.exe
ISVUL: CVE-2019-11043 http://192.168.1.37:8080/index.php

### Download Ladon: https://github.com/k8gege/Ladon
Download Tool