CVE-2010-2263
Description
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
Risk Information
Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
44.217
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update Nginx to 9.1.19 | Windows |
| Update Nginx to 9.1.5 | Windows |
| Update Nginx to 9.1.8 | Windows |
| Update Nginx to 9.2.14 | Windows |
| Update Nginx to 9.2.19 | Windows |
| Update Nginx to 9.2.3 | Windows |
| Update Nginx to 9.2.7 | Windows |
| Update Nginx to 9.3.10 | Windows |
| Update Nginx to 9.3.15 | Windows |
| Update Nginx to 9.3.17 | Windows |
| Update Nginx to 9.1.19 (For Linux) | Linux |
| Update Nginx to 9.1.5 (For Linux) | Linux |
| Update Nginx to 9.1.8 (For Linux) | Linux |
| Update Nginx to 9.2.14 (For Linux) | Linux |
| Update Nginx to 9.2.19 (For Linux) | Linux |
| Update Nginx to 9.2.3 (For Linux) | Linux |
| Update Nginx to 9.2.7 (For Linux) | Linux |
| Update Nginx to 9.3.10 (For Linux) | Linux |
| Update Nginx to 9.3.15 (For Linux) | Linux |
| Update Nginx to 9.3.17 (For Linux) | Linux |
| Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2263) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234