CVE-2010-2266

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
15/06/2010
Last modified:
11/04/2025

Description

nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* 0.7.52 (including) 0.7.67 (excluding)
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* 0.8.0 (including) 0.8.40 (including)