Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2017-7529- — Docker-based reproduction environment for CVE-2017-7529 Nginx integer overflow vulnerability, demonstrating information disclosure via crafted Range headers with step-by-step exploitation guide. | Kitploit
Tools/GitHubGitHub/youngmin0104/cve-2017-7529-
Vulnerability AnalysisExploitationInformation GatheringWeb SecurityLearning & EducationLabs & Practice
GitHubyoungmin0104/cve-2017-7529-

CVE-2017-7529-

Docker-based reproduction environment for CVE-2017-7529 Nginx integer overflow vulnerability, demonstrating information disclosure via crafted Range headers with step-by-step exploitation guide.

View Repository
141 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2017-7529-Nginx Range Header Integer Overflow

  • Nginx is an open-source web server widely used as a high-performance web server, reverse proxy, cache server, and more.

  • In Nginx versions up to 1.13.2, an integer overflow vulnerability exists that allows an attacker to manipulate the Range header and leak memory fragments or sensitive information beyond the original response range.


Reference

  • https://www.freebuf.com/articles/web/140178.html

Vulnerable Environment Setup

  • Start a vulnerable Nginx environment with the following command:
bash
docker compose up -d
  • Once the server is started, you can access it in your browser at the following address:
arduino
http://your-ip:8080
  • The default Nginx page or a custom index.html page will be displayed.

Vulnerability Reproduction

  • Send a malicious Range header request using curl:
bash
curl -v -H "Range: bytes=-9223372036854,5" http://your-ip:8080/

-> The response body may contain strange binary data or memory garbage in addition to part of the page.


How It Works

  • This vulnerability occurs when handling Range requests: an overflow in the integer calculation of negative and positive values causes the response to include memory regions that were not originally intended.
  • This allows an attacker to extract cached data or parts of sensitive information.

Conclusion

  • This vulnerability can cause information disclosure with just a simple HTTP request.

  • If sensitive configuration information or other leakable data is included, it can lead to a serious security incident.

  • Patch: Upgrading to Nginx 1.13.3 or later is recommended.


Example File Structure

bash

CVE-2017-7529/
├── Dockerfile
├── docker-compose.yml
├── nginx.conf
├── index.html
└── README.md  <-- 본 문서
Download Tool