CVE-2010-2266
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
- Affected products
- Nginx
- f5 Nginx
- < 0.7.67, 0.8.40
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 21.5% (97th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2010-06-14
CVE-2010-2266 at NVD
1 known exploit for CVE-2010-2266
Proof-of-concept code and exploit modules indexed by Sploitus