Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-4487

Опубликовано: 13 янв. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:f5:nginx:0.7.64:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.00932
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
больше 15 лет назад

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

redhat
больше 15 лет назад

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

msrc
больше 4 лет назад

Описание отсутствует

debian
больше 15 лет назад

nginx 0.7.64 writes data to a log file without sanitizing non-printabl ...

github
около 3 лет назад

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

EPSS

Процентиль: 75%
0.00932
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo