[GH-ISSUE #2966] When "block common exploits" is enabled, is there a way to bypass certain rules? #2021

Closed
opened 2026-02-26 07:33:43 +03:00 by kerem · 2 comments
Owner

Originally created by @africa1207 on GitHub (May 31, 2023).
Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/2966

I have a PHP application that can be accessed via HTTPS by configuring proxy rules in Nginx (I have enabled block common exploits in Nginx). For example, I can access the application using URLs like https://demo.test.com/my.php or https://demo.test.com/app/other.php. However, when I try to access https://demo.test.com/app/other.php?img=/source/test.jpg, it returns a 403 error due to triggering a vulnerability policy. I cannot modify the PHP application. Is there a way to solve this issue by customizing the proxy rule configuration or using advanced configurations?

Originally created by @africa1207 on GitHub (May 31, 2023). Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/2966 I have a PHP application that can be accessed via HTTPS by configuring proxy rules in Nginx (I have enabled block common exploits in Nginx). For example, I can access the application using URLs like https://demo.test.com/my.php or https://demo.test.com/app/other.php. However, when I try to access https://demo.test.com/app/other.php?img=/source/test.jpg, it returns a 403 error due to triggering a vulnerability policy. I cannot modify the PHP application. Is there a way to solve this issue by customizing the proxy rule configuration or using advanced configurations?
kerem 2026-02-26 07:33:43 +03:00
  • closed this issue
  • added the
    stale
    label
Author
Owner

@github-actions[bot] commented on GitHub (Jan 18, 2024):

Issue is now considered stale. If you want to keep it open, please comment 👍

<!-- gh-comment-id:1897634265 --> @github-actions[bot] commented on GitHub (Jan 18, 2024): Issue is now considered stale. If you want to keep it open, please comment :+1:
Author
Owner

@github-actions[bot] commented on GitHub (Mar 4, 2025):

Issue was closed due to inactivity.

<!-- gh-comment-id:2695994897 --> @github-actions[bot] commented on GitHub (Mar 4, 2025): Issue was closed due to inactivity.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nginx-proxy-manager-NginxProxyManager#2021
No description provided.