CVE-2010-2263
published 2010-06-15CVE-2010-2263: nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files…
PriorityP353medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
74.33%
99.4th percentile
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | — | — |
| f5 | nginx | >= 0.7.52 < 0.7.66 | 0.7.66 |
| f5 | nginx | 0.8.0 – 0.8.39 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests containing the NTFS Alternate Data Stream suffix '::$DATA' or '::$data' appended to any URI path — this is the sole attack vector for CVE-2010-2263 on nginx/Windows. ↗
- →Scope detection to nginx instances running on Windows/NTFS only; Unix deployments are not affected by this vulnerability. ↗
- →Flag nginx versions 0.7.x prior to 0.7.66 and 0.8.x prior to 0.8.40 on Windows as vulnerable; the Metasploit auxiliary module 'scanner/http/nginx_source_disclosure' can be used to confirm exposure. ↗
- ·Vulnerability is exclusively triggered on Windows (NTFS file system); nginx on Unix/Linux is not affected regardless of version. ↗
- ·Fixed versions are nginx 0.7.66 and 0.8.40 on Windows; all earlier 0.7.x and 0.8.x Windows builds are vulnerable. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.0LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-2263: nginx - nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows r...
vendor_debian·2010·CVSS 5.0
CVE-2010-2263 [MEDIUM] CVE-2010-2263: nginx - nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows r...
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-2rq5-xfv5-vq54: nginx 0
ghsa_unreviewed·2022-05-13
CVE-2010-2263 [MEDIUM] CWE-200 GHSA-2rq5-xfv5-vq54: nginx 0
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
No detection rules found.
Exploit-DB
Nginx 0.7.65/0.8.39 (dev) - Source Disclosure / Download
exploitdb·2010-06-11
CVE-2010-2263 Nginx 0.7.65/0.8.39 (dev) - Source Disclosure / Download
Nginx 0.7.65/0.8.39 (dev) - Source Disclosure / Download
---
TITLE: NGINX [ENGINE X] SERVER http://nginx.org/en/ [ref-1]
======TESTED VERSIONS=====
Unix versions are not vulnerable (it only affects to NTFS file system)
Windows Stable versions:
nginx/0.7.66 --> Not vulnerable
nginx/0.7.65 --> Vulnerable
nginx/0.7.64 --> Vulnerable
nginx/0.7.63 --> Vulnerable
nginx/0.7.62 --> Vulnerable
nginx/0.7.61 --> Vulnerable
nginx/0.7.60 --> Vulnerable
nginx/0.7.59 --> Vulnerable
nginx/0.7.58 --> Vulnerable
nginx/0.7.56 --> Vulnerable
Windows Development versions:
nginx/0.8.40 --> Not vulnerable
nginx/0.8.39 --> Vulnerable
nginx/0.8.38 --> Vulnerable
nginx/0.8.37 --> Vulnerable
nginx/0.8.36 --> Vulnerable
nginx/0.8.35 --> Vulnerable
nginx/0.8.34 --> Vulnerable
nginx/0.8.33 --> Vulnerable
nginx/
Exploit-DB
Nginx 0.8.36 - Source Disclosure / Denial of Service
exploitdb·2010-06-11
CVE-2010-2266 Nginx 0.8.36 - Source Disclosure / Denial of Service
Nginx 0.8.36 - Source Disclosure / Denial of Service
---
Issue 1: (Remote Source Disclosure)
- Description -
nginx 0.8.36 is a multi platform HTTP server. This vulnerability exists in the latest Windows version of the application available.
nginx on Windows is vulnerable to a remote source disclosure attack.
- Technical Details - (Source Download)
http://[ webserver IP][:port]index.html::$DATA
Issue 2: (Remote DoS (w/ Memory Corruption))
- Description -
nginx 0.8.36 (Windows) does not seem to handle encoded directory traversal attempts properly. The corrupted registers in the crash dump seem to be loaded with damaged path variables.
- Technical Details - (Remote DoS)
http://[ webserver IP][:port]/%c0.%c0./%c0.%c0./%c0.%c0./%c0.%c0./%20
http://[ webserver IP][:port]/%c0.%c0./%c0
Metasploit
Nginx Source Code Disclosure/Download
metasploit
Nginx Source Code Disclosure/Download
Nginx Source Code Disclosure/Download
This module exploits a source code disclosure/download vulnerability in versions 0.7 and 0.8 of the nginx web server. Versions 0.7.66 and 0.8.40 correct this vulnerability.
No writeups or analysis indexed.
http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.htmlhttp://www.exploit-db.com/exploits/13818http://www.exploit-db.com/exploits/13822http://www.securityfocus.com/bid/40760http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.htmlhttp://www.exploit-db.com/exploits/13818http://www.exploit-db.com/exploits/13822http://www.securityfocus.com/bid/40760
2010-06-15
Published