CVE-2009-3898
published 2009-11-24CVE-2009-3898: Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote…
PriorityP337medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EXPLOIT
EPSS
15.89%
96.5th percentile
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
Affected
290 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 0.7.63-1 (bookworm) | nginx 0.7.63-1 (bookworm) |
| f5 | nginx | <= 0.7.62 | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv4.9MEDIUM
vendor_debian4.9LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-3898: nginx - Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in n...
vendor_debian·2009·CVSS 4.9
CVE-2009-3898 [MEDIUM] CVE-2009-3898: nginx - Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in n...
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
Scope: local
bookworm: resolved (fixed in 0.7.63-1)
bullseye: resolved (fixed in 0.7.63-1)
forky: resolved (fixed in 0.7.63-1)
sid: resolved (fixed in 0.7.63-1)
trixie: resolved (fixed in 0.7.63-1)
GHSA
GHSA-787j-9hgf-jxj6: Directory traversal vulnerability in src/http/modules/ngx_http_dav_module
ghsa_unreviewed·2022-05-02
CVE-2009-3898 [MEDIUM] CWE-22 GHSA-787j-9hgf-jxj6: Directory traversal vulnerability in src/http/modules/ngx_http_dav_module
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
OSV
CVE-2009-3898: Directory traversal vulnerability in src/http/modules/ngx_http_dav_module
osv·2009-11-24·CVSS 4.9
CVE-2009-3898 [MEDIUM] CVE-2009-3898: Directory traversal vulnerability in src/http/modules/ngx_http_dav_module
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0379.htmlhttp://marc.info/?l=oss-security&m=125897327321676&w=2http://marc.info/?l=oss-security&m=125897425223039&w=2http://marc.info/?l=oss-security&m=125900327409842&w=2http://secunia.com/advisories/36818http://secunia.com/advisories/48577http://security.gentoo.org/glsa/glsa-201203-22.xmlhttp://www.openwall.com/lists/oss-security/2009/11/20/1http://www.openwall.com/lists/oss-security/2009/11/23/10http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0379.htmlhttp://marc.info/?l=oss-security&m=125897327321676&w=2http://marc.info/?l=oss-security&m=125897425223039&w=2http://marc.info/?l=oss-security&m=125900327409842&w=2http://secunia.com/advisories/36818http://secunia.com/advisories/48577http://security.gentoo.org/glsa/glsa-201203-22.xmlhttp://www.openwall.com/lists/oss-security/2009/11/20/1http://www.openwall.com/lists/oss-security/2009/11/23/10
2009-11-24
Published