Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
BID:54331
Info
Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
| Bugtraq ID: | 54331 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3380 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2012 12:00AM |
| Updated: | Mar 19 2015 08:35AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
The Naxsi Module for Nginx is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Naxsi 0.46 is vulnerable.
The Naxsi Module for Nginx is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Naxsi 0.46 is vulnerable.
Solution / Fix
Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.