A docker container vulnerable to Shellshock - CVE-2014-6271
podman build -t shellshock-victim .
podman run -it -p 80:8080 shellshock-victim
Note: Builds with docker as well.
The vulnerable app will be deployed on :
http://localhost:8080/victim.cgi
- Vulnerable endpointhttp://localhost:8080/safe.cgi
- Safe endpoint