CVE-2010-2263

NameCVE-2010-2263
Descriptionnginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nginx (PTS)bookworm1.22.1-9+deb12u9fixed
bookworm (security)1.22.1-9+deb12u10fixed
trixie1.26.3-3+deb13u7fixed
trixie (security)1.26.3-3+deb13u9fixed
forky, sid1.30.4-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nginxsource(unstable)(not affected)

Notes

- nginx <not-affected> (Windows-specific vulnerability when running on NTFS)

Search for package or bug name: Reporting problems