← All CVEs

CVE-2010-2263

medium · 5

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.

5
CVSS
71.9%
EPSS (exploit prob.)
99th
EPSS percentile
2010-06-15
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
f5nginx>= 0.7.52, < 0.7.66
f5nginx>= 0.8.0, <= 0.8.39
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-2263