Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-3380
HistoryAug 31, 2012 - 6:55 p.m.

CVE-2012-3380

2012-08-3118:55:03
Debian Security Bug Tracker
security-tracker.debian.org
7
cve-2012-3380
naxsi module
directory traversal
nginx
arbitrary files
unix

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

Related for DEBIANCVE:CVE-2012-3380