Description
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
Remediation
References
Related Vulnerabilities
MongoDb Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6494)
SharePoint Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-3895)
WordPress Cross-Site Scripting Vulnerability (3.9 - 4.1.1)
PHP Observable Discrepancy Vulnerability (CVE-2024-2408)
MOVEit Transfer Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2026-10699)