Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.100277
Category:Web Servers
Title:nginx Proxy DNS Cache Domain Spoofing Vulnerability
Summary:nginx is prone to a vulnerability that may allow attackers to spoof; domains because the software fails to properly compare domains when referencing an internal DNS cache.
Description:Summary:
nginx is prone to a vulnerability that may allow attackers to spoof
domains because the software fails to properly compare domains when referencing an internal DNS cache.

Vulnerability Impact:
This issue can be exploited when nginx is configured to act as a forward
proxy, but this is a nonstandard and unsupported configuration. Attacks against other configurations may
also be possible.

Successful exploits may allow remote attackers to intercept traffic intended for legitimate websites, which may
aid in further attacks.

Solution:
No known solution was made available for at least one year since the
disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade
to a newer release, disable respective features, remove the product or replace the product by another one.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.