Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-41741 PoC — NGINX ngx_http_mp4_module vulnerability CVE-2022-41741

Source
Associated Vulnerability
Title:NGINX ngx_http_mp4_module vulnerability CVE-2022-41741 (CVE-2022-41741)
Description:NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Description
CVE-2022-41741/742 Nginx Vulnerability Scanner
Readme
# 🛡️ Nginx Vulnerability Scanner
Desarrollado por **m10sec**.

Este script detecta automáticamente la versión de Nginx en un servidor remoto y evalúa si es vulnerable a fallos de seguridad conocidos, específicamente:

- **CVE-2023-44487** – HTTP/2 Rapid Reset Attack
- **CVE-2022-41741** – Corrupción de memoria en `ngx_http_mp4_module`
- **CVE-2022-41742** – Revelación de memoria en `ngx_http_mp4_module`

---

## 🚀 Características

- Solicita al usuario una URL o IP del servidor a analizar.
- Detecta si el servidor está usando Nginx y extrae su versión.
- Verifica si está activo el módulo `ngx_http_mp4_module`.
- Determina si el servidor puede ser vulnerable a las CVEs mencionadas.
- Informa recomendaciones de mitigación si aplica.

---

## 📥 Requisitos

- Python 3.6+
- Librerías:
  ```bash
  pip install requests packaging
File Snapshot

[4.0K] /data/pocs/f463f1f2cc7fcd566ecaa183819eb4fd71740960 ├── [3.7K] CVE-2022-41741:742.py └── [ 864] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →