CVE-2010-2266

F5 Nginx < 0.7.67 - Path Traversal

Title source: rule
STIX 2.1

Description

nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dr_IDE · textremotewindows
https://www.exploit-db.com/exploits/13818

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/13818/

Scores

EPSS 0.0726
EPSS Percentile 91.7%

Details

CWE
CWE-22
Status published
Products (1)
f5/nginx 0.7.52 - 0.7.67
Published Jun 15, 2010
Tracked Since Feb 18, 2026