cbcvebase.
CVE-2009-3898
published 2009-11-24

CVE-2009-3898: Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote…

PriorityP337medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EXPLOIT
EPSS
15.89%
96.5th percentile
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.

Affected

290 ranges· showing 25
VendorProductVersion rangeFixed in
debiannginx< nginx 0.7.63-1 (bookworm)nginx 0.7.63-1 (bookworm)
f5nginx<= 0.7.62
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx
f5nginx

CVSS provenance

nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv4.9MEDIUM
vendor_debian4.9LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.