Files
CVEs-PoC/2020/CVE-2020-21699.md
T
2024-05-25 21:48:12 +02:00

18 lines
780 B
Markdown

### [CVE-2020-21699](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-21699)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
### POC
#### Reference
- https://github.com/ZxDecide/Nginx-variants/blob/master/%E9%99%84%E4%BB%B6(Tengine).docx
#### Github
No PoCs found on GitHub currently.