CVE-2010-2263
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
- Affected products
- Nginx
- f5 Nginx
- < 0.7.66, 0.8.39
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 71.9% (99th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2010-06-14
CVE-2010-2263 at NVD
5 known exploits for CVE-2010-2263
Proof-of-concept code and exploit modules indexed by Sploitus