CVE-2009-3898
EPSS 15.9%
描述
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
如何修補 CVE-2009-3898
要修補 CVE-2009-3898,請將受影響套件升級到下列已修補版本。
- Debian/nginx—升級至 0.7.63-1 或更新版本
CVE-2009-3898 正在被利用嗎?
中等 — EPSS 為 15.9%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 0.7.63-1