Description
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
Remediation
References
Related Vulnerabilities
WordPress Plugin AddToAny Share Buttons Cross-Site Scripting (1.7.47)
WordPress 3.8.x PHP Object Injection (3.8 - 3.8.35)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-0682)
WordPress Plugin UpiCRM-Free WordPress CRM and Lead Management Information Disclosure (2.1.8.5)