语言:
http://bh.ht.vc/vhost_confusion.pdf
http://nginx.org/en/security_advisories.html
http://mailman.nginx.org/pipermail/nginx-announce/2014/000146.html
http://mailman.nginx.org/pipermail/nginx-announce/2014/000145.html
http://mailman.nginx.org/pipermail/nginx-announce/2014/000147.html
严重性: Medium
ID: 78386
文件名: nginx_1_7_5.nasl
版本: 1.14
类型: combined
代理: unix
系列: Web Servers
发布时间: 2014/10/13
最近更新时间: 2022/4/11
配置: 启用全面检查
支持的传感器: Nessus Agent, Nessus
CVSS 分数理由: The nvd score does not account for the potential for the virtual host confusion attack being used to access confidential data (as detailed in the original virtual host confusion: weaknesses and exploits blackhat 2014 paper from antoine delignat-lavaud)
风险因素: Medium
分数: 5.9
风险因素: Medium
基本分数: 4
时间分数: 3
矢量: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N
CVSS 分数来源: manual
风险因素: Medium
基本分数: 5.3
时间分数: 4.6
矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
时间矢量: CVSS:3.0/E:U/RL:O/RC:C
CPE: cpe:/a:nginx:nginx
必需的 KB 项: installed_sw/nginx
易利用性: No known exploits are available
补丁发布日期: 2014/9/16
漏洞发布日期: 2014/8/6
CVE: CVE-2014-3616
BID: 70025