PT-2010-3852 · Nginx · Nginx

Dr_Ide

·

Published

2010-06-14

·

Updated

2021-11-10

·

CVE-2010-2266

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions nginx version 0.8.36
Description The issue allows remote attackers to cause a denial of service, leading to a crash, via certain encoded directory traversal sequences that trigger memory corruption. An example of such a sequence is the "%c0.%c0." sequence.
Recommendations For nginx version 0.8.36, update to a newer version to mitigate the risk of denial of service attacks.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2266

Affected Products

Nginx