Lucene search

K
cvelistRedhatCVELIST:CVE-2009-3898
HistoryNov 24, 2009 - 5:00 p.m.

CVE-2009-3898

2009-11-2417:00:00
redhat
www.cve.org
1

6.1 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.1%

Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a … (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.

6.1 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.1%