CVE-2011-4963: F5 Nginx
Medium severity, CVSS 5.0. EPSS: 6% chance of exploitation in the next 30 days.
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
Affected products
- F5 Nginx: from 0.7.52, before 1.2.1 (fixed in 1.2.1); version 1.3.0 only
Published 2012-07-26. Last modified 2026-06-16.