peter bassill · operator
$ cve CVE-2010-2263 JSON

CVE-2010-2263 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 71.9% (pctl 99)

Patch early

A public exploit exists.

Description

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS71.93% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2010-06-15
Last modified2026-06-16

Affected (2)

VendorProduct
f5nginx
microsoftwindows

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD