CVE-2009-4487 describes a vulnerability in nginx version 0.7.64 where it fails to sanitize non-printable characters in log files. This flaw allows remote attackers to inject terminal escape sequences via HTTP requests, potentially leading to window title modification, arbitrary command execution, or file overwrites. With a CVSS score of 6.8 (Medium), it has a network attack vector, medium attack complexity, and partial impact on confidentiality, integrity, and availability. While not actively exploited in the wild and not on CISA's KEV catalog, an ExploitDB entry exists (EDB-33490) demonstrating command injection, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.7.64CPE matchmatch criteria | cpe:2.3:a:f5:nginx:0.7.64:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2009-4487
Nov 10, 2020nginx: Absent sanitation of escape sequences in web server log
Jan 10, 2010nginx 0.7.64 writes data to a log file without sanitizing non-printable characters which might allow remote attackers to modify a window's title or possibly execute arbitrary commands or overwrite files via an HTTP request containing an escape sequence for a terminal emulator.
Jan 2, 2010An error log data are not sanitized
Jan 1, 2009An error log data are not sanitized
Jan 1, 2009An error log data are not sanitized
Jan 1, 2009An error log data are not sanitized
Jan 1, 2009An error log data are not sanitized
An error log data are not sanitized
An error log data are not sanitized
An error log data are not sanitized