Vulnerabilities > CVE-2009-4487 - Unspecified vulnerability in F5 Nginx 0.7.64
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Exploit-Db
description | nginx 0.7.64 Terminal Escape Sequence in Logs Command Injection Vulnerability. CVE-2009-4487. Remote exploits for multiple platform |
id | EDB-ID:33490 |
last seen | 2016-02-03 |
modified | 2010-01-11 |
published | 2010-01-11 |
reporter | evilaliv3 |
source | https://www.exploit-db.com/download/33490/ |
title | nginx 0.7.64 Terminal Escape Sequence in Logs Command Injection Vulnerability |
Nessus
NASL family | Web Servers |
NASL id | NGINX_0_7_64.NASL |
description | According to the self-reported version in its response header, the version of nginx hosted on the remote web server is less than 0.7.64 or 0.8.x prior to 0.8.23. It is, therefore, affected by multiple vulnerabilities as noted in the vendor advisory. |
last seen | 2020-05-09 |
modified | 2018-03-09 |
plugin id | 107262 |
published | 2018-03-09 |
reporter | This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/107262 |
title | nginx < 0.7.64 / 0.8.x < 0.8.23 Multiple Vulnerabilities |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/85018/log-inject.txt |
id | PACKETSTORM:85018 |
last seen | 2016-12-05 |
published | 2010-01-11 |
reporter | Francesco Ongaro |
source | https://packetstormsecurity.com/files/85018/Nginx-Varnish-Cherokee-etc-Log-Injection.html |
title | Nginx, Varnish, Cherokee, etc Log Injection |