vendor:
Nginx [Engine X] Server
by:
Jose A. Vazquez
7,5
CVSS
HIGH
Source Code Disclosure/Download Vulnerability
N/A
CWE
Product Name: Nginx [Engine X] Server
Affected Version From: nginx/0.7.65
Affected Version To: nginx/0.8.39
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3/ Windows 7 Home Premium
2010
NGINX [ENGINE X] SERVER <= 0.7.65 (STABLE)/0.8.39 (DEVELOPMENT) SOURCE CODE DISCLOSURE/DOWNLOAD VULNERABILITY
This application was vulnerable to source code disclosure/download vulnerability when it was running in Windows OS (NTFS file system). App parser couldn't handle ADS (Alternate Data Streams) and it treated a data stream as an usual file. An Attacker could read/download source code of webapps files using default data stream (unnamed): 'filename::$data'.
Mitigation:
Upgrade to the latest version of Nginx (0.8.40 or 0.7.66).