CVE-2009-3898: Path Traversal
Directory traversal vulnerability in src/http/modules/ngxhttpdavmodule.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3898?
CVE-2009-3898 is classified as a high severity vulnerability, allowing remote authenticated users to exploit directory traversal.
How do I fix CVE-2009-3898?
To fix CVE-2009-3898, upgrade to nginx version 0.7.63 or 0.8.17 or later, which includes the necessary patches.
What types of attacks are possible with CVE-2009-3898?
CVE-2009-3898 enables attackers to create or overwrite arbitrary files on the server via WebDAV operations.
Who is affected by CVE-2009-3898?
CVE-2009-3898 affects nginx versions prior to 0.7.63 and 0.8.x before 0.8.17.
What is the impact of exploiting CVE-2009-3898?
Exploiting CVE-2009-3898 can lead to unauthorized file manipulations, potentially compromising server security and integrity.