Nginx 1.1.17 - URI Processing SecURIty Bypass



EKU-ID: 43217 CVE: CVE-2013-4547;OSVDB-100015 OSVDB-ID:
Author: Ivan Fratric Published: 2013-11-19 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/63814/info

nginx is prone to a remote security-bypass vulnerability.

An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions.

nginx 0.8.41 through 1.5.6 are vulnerable.

The following example data is available:

/file \0.php