imPC@ndo IT

Tracker / CVE-2013-4547

CVE-2013-4547

High 7.5

nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.

Affected products and versions

f5 nginx · 0.8.41 → 1.4.4
f5 nginx · 1.5.0 → 1.5.6
opensuse opensuse
suse lifecycle_management_server
suse studio_onsite
suse webyast

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References