Vulnerabilities/

Nginx Null Byte Code Execution

Impact: High

Description

Null byte character (ASCII 0x00) is allowed in the URL. If the user can control the contents of files on the server, this can result in the arbitrary PHP code execution.

Recommendation

Upgrade the Nginx.

References

Last updated on February 15, 2021

This issue is available in SmartScanner Professional

See Pricing