Summary
nginx is prone to a remote source code-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view the source code of files in the context of the server process, which may aid in further attacks.
This issue affects nginx versions prior to 0.8.36.
Solution
Reportedly, the issue is fixed in version 0.8.36. Please contact the vendor for more information.
References
Updated on 2015-03-25
Severity
Classification
-
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities
- Apache Tomcat Partial HTTP Requests DoS Vulnerability (Windows)
- GoAhead Webserver Multiple Stored Cross Site Scripting Vulnerabilities
- IBM WebSphere Application Server (WAS) Cross-site Scripting Vulnerability
- Check for dangerous IIS default files
- Apache HTTP Server 'mod_dav_svn' Denial of Service Vulnerability (Windows)