PT-2010-3849 · Nginx · Nginx

Jose Antonio Vazquez Gonzalez

·

Publicado

2010-06-14

·

Atualizado

2021-11-10

·

CVE-2010-2263

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions nginx versions 0.8 before 0.8.40 nginx versions 0.7 before 0.7.66
Description The issue allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI, but only when running on Windows.
Recommendations For nginx versions 0.8 before 0.8.40, update to version 0.8.40 or later. For nginx versions 0.7 before 0.7.66, update to version 0.7.66 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2263

Produtos afetados

Nginx