{"api_version":"1","generated_at":"2026-07-23T11:06:19+00:00","cve":"CVE-2010-2263","urls":{"html":"https://cve.report/CVE-2010-2263","api":"https://cve.report/api/cve/CVE-2010-2263.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2263","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2263"},"summary":{"title":"CVE-2010-2263","description":"nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-06-15 14:04:24","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html","name":"http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Release Notes","Third Party Advisory"],"title":":::::0th3r ****ing S3Cbl0g:::: Only 4 Fun & pr0fit ;): :::FULL & RESPONSIBLE DISCLOSURE:::NGINX [ENGINE X] SERVER <= 0.7.65 /0.8.39 SOURCE CODE DISCLOSURE/DOWNLOAD VULN. (CVE-2010-2263)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/13822","name":"http://www.exploit-db.com/exploits/13822","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Nginx <= 0.7.65 / 0.8.39 (dev) Source Disclosure / Download Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/40760","name":"http://www.securityfocus.com/bid/40760","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.exploit-db.com/exploits/13818","name":"http://www.exploit-db.com/exploits/13818","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Nginx 0.8.36 Source Disclosure and DoS Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2263","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2263","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2263","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"f5","cpe5":"nginx","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2263","vulnerable":"1","versionEndIncluding":"0.8.39","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"f5","cpe5":"nginx","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2263","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:25:07.565Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"13818","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/13818"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html"},{"name":"13822","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/13822"},{"name":"40760","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/40760"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-06-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-11-16T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"13818","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/13818"},{"tags":["x_refsource_MISC"],"url":"http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html"},{"name":"13822","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/13822"},{"name":"40760","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/40760"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-2263","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"13818","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/13818"},{"name":"http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html","refsource":"MISC","url":"http://spa-s3c.blogspot.com/2010/06/full-responsible-disclosurenginx-engine.html"},{"name":"13822","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/13822"},{"name":"40760","refsource":"BID","url":"http://www.securityfocus.com/bid/40760"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-2263","datePublished":"2010-06-14T18:00:00.000Z","dateReserved":"2010-06-11T00:00:00.000Z","dateUpdated":"2024-08-07T02:25:07.565Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-06-15 14:04:24","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*","versionStartIncluding":"0.7.52","versionEndExcluding":"0.7.66","matchCriteriaId":"1B338639-BD28-4073-8874-7D4013E23282"},{"vulnerable":true,"criteria":"cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*","versionStartIncluding":"0.8.0","versionEndIncluding":"0.8.39","matchCriteriaId":"494A2664-A392-4F3F-B15A-B31FF474BBB5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2263","Ordinal":"1","Title":"CVE-2010-2263","CVE":"CVE-2010-2263","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2263","Ordinal":"1","NoteData":"nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.","Type":"Description","Title":"CVE-2010-2263"},{"CveYear":"2010","CveId":"2263","Ordinal":"2","NoteData":"2010-06-14","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"2263","Ordinal":"3","NoteData":"2016-11-16","Type":"Other","Title":"Modified"}]}}}