Skip to main content

Vendor/product archive

embedthis / goahead CVEs

Beta · best-effort

17 CVEs tagged to embedthis / goahead6 Critical, 10 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2021-41615

Published Aug 8, 2022

websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which does not follow the s…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43298

Published Jan 25, 2022

The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated ne…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-42342

Published Oct 14, 2021

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15688

Published Jul 23, 2020

The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5097

Published Dec 3, 2019

A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A sp…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-5096

Published Dec 3, 2019

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 an…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-19240

Published Nov 22, 2019

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can o…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16645

Published Sep 20, 2019

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12822

Published Jun 14, 2019

In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and potential DoS, as d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000471

Published Jan 3, 2018

EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17562

Published Dec 12, 2017

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked C…

CVSS 8.1 · High
evidence mentions
4
Buzz score
47.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-14149

Published Sep 5, 2017

GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5675

Published Mar 13, 2017

A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models. The mail-se…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5674

Published Mar 13, 2017

A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2014-9707

Published Mar 31, 2015

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1