
This repository contains a step-by-step, image-backed Proof of Concept (PoC) simulating two vulnerabilities in Nginx Proxy Manager that enable OS Command Injection, leading to Remote Code Execution (RCE) after authentication.
POC.md: Detailed write-up of the analysis and exploitation steps, including payloads and observations.static/: Screenshots referenced by POC.md in the order they appear.POC.md to follow the simulation narrative.static/ to illustrate setup, code review, exploitation, and results.