
Step-by-step, image-backed proof-of-concept simulation of OS command injection vulnerabilities (CVE-2024-46256 and CVE-2024-46257) in Nginx Proxy Manager v2.11.3, demonstrating authenticated remote code execution for educational and defensive research.
This repository contains a step-by-step, image-backed Proof of Concept (PoC) simulating two vulnerabilities in Nginx Proxy Manager that enable OS Command Injection, leading to Remote Code Execution (RCE) after authentication.
POC.md: Detailed write-up of the analysis and exploitation steps, including payloads and observations.static/: Screenshots referenced by POC.md in the order they appear.POC.md to follow the simulation narrative.static/ to illustrate setup, code review, exploitation, and results.