Vulnerabilities > CVE-2009-4487 - Unspecified vulnerability in F5 Nginx 0.7.64
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Exploit-Db
description | nginx 0.7.64 Terminal Escape Sequence in Logs Command Injection Vulnerability. CVE-2009-4487. Remote exploits for multiple platform |
id | EDB-ID:33490 |
last seen | 2016-02-03 |
modified | 2010-01-11 |
published | 2010-01-11 |
reporter | evilaliv3 |
source | https://www.exploit-db.com/download/33490/ |
title | nginx 0.7.64 Terminal Escape Sequence in Logs Command Injection Vulnerability |
Nessus
NASL family | Web Servers |
NASL id | NGINX_0_7_64.NASL |
description | According to the self-reported version in its response header, the version of nginx hosted on the remote web server is less than 0.7.64 or 0.8.x prior to 0.8.23. It is, therefore, affected by multiple vulnerabilities as noted in the vendor advisory. |
last seen | 2020-05-09 |
modified | 2018-03-09 |
plugin id | 107262 |
published | 2018-03-09 |
reporter | This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/107262 |
title | nginx < 0.7.64 / 0.8.x < 0.8.23 Multiple Vulnerabilities |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/85018/log-inject.txt |
id | PACKETSTORM:85018 |
last seen | 2016-12-05 |
published | 2010-01-11 |
reporter | Francesco Ongaro |
source | https://packetstormsecurity.com/files/85018/Nginx-Varnish-Cherokee-etc-Log-Injection.html |
title | Nginx, Varnish, Cherokee, etc Log Injection |
References
- http://www.securityfocus.com/archive/1/508830/100/0/threaded
- http://www.securityfocus.com/archive/1/508830/100/0/threaded
- http://www.securityfocus.com/bid/37711
- http://www.securityfocus.com/bid/37711
- http://www.ush.it/team/ush/hack_httpd_escape/adv.txt
- http://www.ush.it/team/ush/hack_httpd_escape/adv.txt