CVE-2010-2263

N/A Unknown
Published: June 15, 2010 Modified: April 29, 2026
View on NVD

Description

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html
Source: cve@mitre.org
Exploit Release Notes Third Party Advisory
http://www.exploit-db.com/exploits/13818
Source: cve@mitre.org
Exploit Third Party Advisory VDB Entry
http://www.exploit-db.com/exploits/13822
Source: cve@mitre.org
Exploit Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/40760
Source: cve@mitre.org
Exploit Third Party Advisory VDB Entry
http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Release Notes Third Party Advisory
http://www.exploit-db.com/exploits/13818
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Third Party Advisory VDB Entry
http://www.exploit-db.com/exploits/13822
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/40760
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Third Party Advisory VDB Entry

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
44.2%
98th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

microsoft f5