CVE-2010-2263
medium · 5nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
5
CVSS
71.9%
EPSS (exploit prob.)
99th
EPSS percentile
2010-06-15
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| f5 | nginx | >= 0.7.52, < 0.7.66 |
| f5 | nginx | >= 0.8.0, <= 0.8.39 |
| microsoft | windows | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html
- http://www.exploit-db.com/exploits/13818
- http://www.exploit-db.com/exploits/13822
- http://www.securityfocus.com/bid/40760
- http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html
- http://www.exploit-db.com/exploits/13818
- http://www.exploit-db.com/exploits/13822
- http://www.securityfocus.com/bid/40760
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-2263