| ID | CVE-2009-3898 | ||||||
| Sažetak | Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:M/Au:S/C:P/I:P/A:N | ||||||
| Zadnje važnije ažuriranje | 10-11-2021 - 15:52 | ||||||
| Objavljeno | 24-11-2009 - 17:30 |

