CVE-2010-2263 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 71.9% (pctl 99)
Patch early
A public exploit exists.
Description
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 71.93% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-06-15 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| f5 | nginx |
| microsoft | windows |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Nginx 0.8.36 - Source Disclosure / Denial of Service | 2010-06-11 |
| exploit-db | Nginx 0.7.65/0.8.39 (dev) - Source Disclosure / Download | 2010-06-11 |
References
- http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html
- http://www.exploit-db.com/exploits/13818
- http://www.exploit-db.com/exploits/13822
- http://www.securityfocus.com/bid/40760
- http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html
- http://www.exploit-db.com/exploits/13818
- http://www.exploit-db.com/exploits/13822
- http://www.securityfocus.com/bid/40760
→ the Explorer · watch your stack · NVD