Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-4487

46
FAUCET Score

CVE-2009-4487 describes a vulnerability in nginx version 0.7.64 where it fails to sanitize non-printable characters in log files. This flaw allows remote attackers to inject terminal escape sequences via HTTP requests, potentially leading to window title modification, arbitrary command execution, or file overwrites. With a CVSS score of 6.8 (Medium), it has a network attack vector, medium attack complexity, and partial impact on confidentiality, integrity, and availability. While not actively exploited in the wild and not on CISA's KEV catalog, an ExploitDB entry exists (EDB-33490) demonstrating command injection, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
0.7.64CPE matchmatch criteria
cpe:2.3:a:f5:nginx:0.7.64:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
29.52%
Probability of exploitation in next 30 days
EPSS Percentile
98.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-33490 · Jan 11, 2010
This CVE's current EPSS score of 0.2952 is in the 98th percentile among its peer group of 19,956 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

microsoftpatch availablevia msrc
Product: cm1 nginx 1.16.1-4 on CBL Mariner 1.0Fixed in: 1.16.1-4
microsoftpatch availablevia msrc
Product: 17046-16820Fixed in: 1.16.1-4
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.16.1-4
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.16.1-4
dahuavendor investigatingvia llm_extracted
dfinityvendor investigatingvia llm_extracted
jfrogvendor investigatingvia llm_extracted
liferayvendor investigatingvia llm_extracted
netgearvendor investigatingvia llm_extracted
opensshvendor investigatingvia llm_extracted
power_bivendor investigatingvia llm_extracted
terraformvendor investigatingvia llm_extracted

Vendor Advisories (11)

microsoft2020-Nov/CVE-2009-4487

CVE-2009-4487

Nov 10, 2020
redhatCVE-2009-4487Low

nginx: Absent sanitation of escape sequences in web server log

Jan 10, 2010
microsoft2010-Jan/CVE-2009-4487Moderate

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters which might allow remote attackers to modify a window's title or possibly execute arbitrary commands or overwrite files via an HTTP request containing an escape sequence for a terminal emulator.

Jan 2, 2010
dfinityllm-dfinity-aa7e4776cb1883b4

An error log data are not sanitized

Jan 1, 2009
opensshllm-openssh-4561826fc404469e

An error log data are not sanitized

Jan 1, 2009
power_billm-power_bi-43474ea0713d9f56LOW

An error log data are not sanitized

Jan 1, 2009
jfrogllm-jfrog-c642933afe743952

An error log data are not sanitized

Jan 1, 2009
netgearllm-netgear-56689e849f3c9992LOW

An error log data are not sanitized

liferayllm-liferay-c74d565841a6715a

An error log data are not sanitized

terraformllm-terraform-ede91eee051cf305

An error log data are not sanitized

dahuallm-dahua-24a0b1755c1185a1

An error log data are not sanitized

References

securityfocus.com / archive/1/508830/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/37711
Broken LinkThird Party AdvisoryVDB Entry
ush.it / team/ush/hack_httpd_escape/adv.txt
ExploitPatchThird Party Advisory