漏洞关键信息 EDB-ID: 13818 CVE: 2010-2266, 2010-2263 Author: DR_IDE Type: REMOTE Platform: WINDOWS Date: 2010-06-11 Vulnerable App: nginx 0.8.36 Issue 1: Remote Source Disclosure Description: Nginx 0.8.36 on Windows is vulnerable to a remote source disclosure attack. Technical Details: - Source Download URL: Issue 2: Remote DoS (w/ Memory Corruption) Description: - Nginx 0.8.36 (Windows) does not handle encoded directory traversal attempts properly. - Corrupted registers in the crash dump seem to be loaded with damaged path variables. Technical Details: - URLs causing issues: - - - These URLs overwrite memory registers with parts of the internal path, leading to a Denial of Service.