Lucene search

K
cve[email protected]CVE-2009-4487
HistoryJan 13, 2010 - 8:30 p.m.

CVE-2009-4487

2010-01-1320:30:00
web.nvd.nist.gov
98
cve
nginx
log file
vulnerability
http request
security
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

79.8%

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window’s title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

Affected configurations

NVD
Node
f5nginxMatch0.7.64
CPENameOperatorVersion
f5:nginxf5 nginxeq0.7.64

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

79.8%