CVE-2010-2263

F5 Nginx < 0.7.66 - Information Disclosure

Title source: rule

Description

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Dr_IDE · textremotewindows
https://www.exploit-db.com/exploits/13818
exploitdb WRITEUP VERIFIED
by Jose A. Vazquez · textremotewindows
https://www.exploit-db.com/exploits/13822
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/nginx_source_disclosure.rb

Scores

EPSS 0.4422
EPSS Percentile 97.6%

Details

CWE
CWE-200
Status published
Products (1)
f5/nginx 0.7.52 - 0.7.66
Published Jun 15, 2010
Tracked Since Feb 18, 2026