Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-11043-Vulnerability — Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic analysis. | Kitploit
Tools/GitHubGitHub/magentabear/cve-2019-11043-vulnerability
Memory ForensicsPersistence MechanismsVulnerability AnalysisExploitationNetwork ForensicsWeb Application ExploitationPenetration TestingMisconfigurationLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Red Teaming
Labs & Practice
GitHubmagentabear/cve-2019-11043-vulnerability

CVE-2019-11043-Vulnerability

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic analysis.

View Repository
199 months agoNot yet reviewed

Collaberators: Olaf Madejski, Andrew Masone, Nate Desany

PHP-FPM Reverse Tunnel Exploitation & Persistence Demonstration

CVE-2019-11043 — Debian PHP-FPM Path Handling Vulnerability


Project Overview

In October 2019, Debian Security Advisory researchers Emil Lerner and Andrew Danau published a notice warning the Debian community about a critical vulnerability in PHP-FPM. Due to insufficient validation in PHP-FPM’s path handling code, attackers could manipulate specially crafted requests to achieve remote arbitrary code execution under certain NGINX + PHP-FPM configurations.

This lab demonstrates the exploitation of:

CVE-2019-11043

A vulnerability affecting PHP-FPM running behind NGINX that, when triggered, can allow attackers to execute arbitrary code and establish persistence through reverse tunneling.

The project recreates a vulnerable environment, executes the exploit chain, and evaluates how adversaries achieve persistence through tunneling techniques in real-world scenarios.


Table of Contents

Config

  • Contains index.php file which holds the index file for the docker container.
  • Contains patched defualt configuration for nginx and usage of php-fpm.
  • Contains vulnerable defualt configuration for nginx and usage of php-fpm.

Disk_Images

  • Contains text file that points to Google drive holding 2 zip files of the disk image of both virtual machines, the host (Home) and Attacker.

Screenshots

  • Folder containing screenshots throughout the lab and included in the readme.

Supplemental Material

  • README for the 2 tools used for the exploit, as well as the docker compose file for the docker image.

LogFiles

  • Log files ranging from the attacker machine and Host (Home) Machine.
  • These files include .pcap logs split apart for easier use.
  • A link to memory dump, this is important as the exploit inherently uses a memory overflow.
  • access, auth, error, faillog, fulllog.zip (journalctl logs), history, php7.3-fpm (for usage of patching the vulnerability), syslog, and term logs.

README.md

  • Readme file you are reading right now.

Project Relevance

Attack Vector

This attack chain aligns directly with several high-impact MITRE ATT&CK techniques:

MITRE IDTechnique Name
T1071Application Layer Tunneling
T1572Protocol Tunneling
T1090Proxy / Reverse Proxy
T1505Server-Side Components (PHP-FPM)
T1574Hijacking Execution Flow

Why This Matters Today

Reverse tunneling for persistence is a high-frequency TTP (Tactic, Technique, Procedure) used across APT groups, botnets, and ransomware operators. PHP-FPM remains widely deployed in production environments, and the misconfigurations exploited by CVE-2019-11043 are still observed in the wild.

These are not theoretical abstractions — they mirror the exact behaviors documented in active exploitation campaigns involving nation-state actors and ransomware groups.

Even though CVE-2019-11043 is several years old, the vulnerability continues to hold relevance due to the following modern security realities:

  • Legacy PHP applications are still everywhere. Many organizations continue to run outdated PHP 5.x/7.x stacks because of long-term web application dependencies, technical debt, or fear of breaking production systems. These environments often remain unpatched and vulnerable.

  • NGINX + PHP-FPM is one of the most common hosting architectures globally. This makes vulnerabilities in PHP-FPM extremely attractive to attackers who look for large, long-lasting exploitation surfaces.

  • Reverse tunneling is a core persistence technique across modern threats. Groups like Lazarus, APT29, FIN11, and numerous ransomware operators use reverse SSH tunnels, WebSocket tunnels, and even PHP-based reverse shells to maintain long-term access without relying on exposed inbound ports.

  • Misconfigurations remain the #1 cause of breaches. Even when patches exist, misconfigured NGINX “location” blocks and poorly validated PATH_INFO variables continue to expose environments to exploitation.

  • Exploit automation kits still target this CVE. Tools such as automated scanners, botnets, and IoT malware routinely probe for vulnerable PHP-FPM setups because the exploit results in reliable code execution.

  • Cloud environments are expanding the attack surface. Poorly secured containers, shared hosting setups, and outdated Docker base images often contain unpatched PHP-FPM versions, leading to rapid lateral movement inside cloud networks.

  • Attackers love "low hanging fruit." A vulnerability that enables remote code execution + tunnel-based persistence with minimal skill required will always remain a high-value target.

In today's threat landscape, where persistent access, stealthy tunneling, and supply-chain weaknesses dominate cybersecurity headlines, understanding and demonstrating how CVE-2019-11043 is exploited provides critical insight into modern attack patterns and defensive gaps.


Methodology

Environment

The objective of this lab was to simulate a real‑world exploitation of CVE‑2019‑11043, a critical remote code execution vulnerability affecting PHP‑FPM behind nginx using certain configurations. The goal was to analyze the vulnerability, reproduce the exploit in a controlled virtual environment, and demonstrate the risks associated with misconfigured web infrastructure.

Two virtual machines were used: both with a username of username and password of password.

RoleMachineIP AddressPurpose
Target / VictimUbuntu Server192.168.56.102Vulnerable PHP-FPM server running CVE-2019-11043
AttackerUbuntu Server192.168.56.103Executes exploit, reverse shell, and persistence

Commands for host setup:

Update apt

sudo apt update && sudo apt -y upgrade

Making the container for the vulnerability exploit.

sudo apt install -y docker.io docker-compose git
git clone https://github.com/vulhub/vulhub.git
cd vulhub/php/CVE-2019-11043
sudo docker-compose up -d

Commands for target setup:

Update Apt, and install basic php and python and more packages

sudo apt update
sudo apt install nmap curl wget git python3 python3-pip \
    netcat-traditional net-tools build-essential \
    php ruby ruby-full        
pip3 install requests
sudo apt install golang-go

Downloads a tool to exploit the CVE in question and moves the terminal to build the exploit.

git clone https://github.com/neex/phuip-fpizdam.git
cd phuip-fpizdam
go build

Commands for attacking the target:

From here setup is complete, for example of what you can do first,

  1. In one terminal (terminal 1) perform:
Download Tool