nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.exploit-db.com/exploits/13818 | third party advisory vdb entry exploit |
http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html | third party advisory release notes exploit |
http://www.exploit-db.com/exploits/13822 | third party advisory vdb entry exploit |
http://www.securityfocus.com/bid/40760 | third party advisory vdb entry exploit |