cbcvebase.
CVE-2013-4547
published 2013-11-23

CVE-2013-4547: nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.

high7.5CVSS 3.1
AVNACLAuNCPIPAP
EXPLOIT
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiannginx< nginx 1.4.4-1 (bookworm)nginx 1.4.4-1 (bookworm)
f5nginx>= 0 < 1.4.4-11.4.4-1
f5nginx>= 0 < 1.4.4-11.4.4-1
f5nginx>= 0 < 1.4.4-11.4.4-1
f5nginx>= 0 < 1.4.4-11.4.4-1
f5nginx>= 0.8.41 < 1.4.41.4.4
f5nginx1.5.0 – 1.5.6
opensuseopensuse
opensuseopensuse
opensuseopensuse
opensuseopensuse
suselifecycle_management_server
susestudio_onsite
susewebyast

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH