8 results (0.001 seconds)

CVSS: 5.0EPSS: 0%CPEs: 7EXPL: 0

GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function. GoAhead WebServer anterior a v2.1.6 permite a atacantes remotos provocar una denegación de servicio (referencia a puntero nulo o caída de demonio) a través de una URL invalida, relacionada con la función websSafeUrl. • http://data.goahead.com/Software/Webserver/2.1.8/release.htm#null-pointer-crash-in-webssafeurl • CWE-20: Improper Input Validation •

CVSS: 5.0EPSS: 1%CPEs: 2EXPL: 1

goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603. goform/QuickStart_c0 sobre GoAhead Web Server en el dispositivo VDSL FS4104-AW (también conocido como rooter), permite la lectura del password del campo typepassword a través del código HTML. Vulnerabilidad distinta a CVE-2002-1603. • https://www.exploit-db.com/exploits/4744 http://osvdb.org/43168 https://exchange.xforce.ibmcloud.com/vulnerabilities/39149 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 7%CPEs: 1EXPL: 3

Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories. • https://www.exploit-db.com/exploits/21707 http://freecode.com/projects/embedthis-goahead-webserver/releases/343539 http://osvdb.org/81099 http://www.iss.net/security_center/static/9884.php http://www.securiteam.com/securitynews/5MP0C1580W.html http://www.securityfocus.com/bid/5464 •

CVSS: 7.5EPSS: 7%CPEs: 5EXPL: 2

Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script. Vulnerabilidad de secuencias de comandos en sitios cruzados (cross-site scripting) en GoAhead Web Server 2.1 permite a atacantes remotos ejecutar secuencias de comandos como otros usuarios web mediante un script en una URL que genera un mensaje "404 no encontrado", que no le pone comillas al script. • https://www.exploit-db.com/exploits/21608 http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0013.html http://freecode.com/projects/embedthis-goahead-webserver/releases/343539 http://marc.info/?l=bugtraq&m=102631742711795&w=2 http://osvdb.org/81099 http://www.iss.net/security_center/static/9518.php http://www.securityfocus.com/bid/5198 •

CVSS: 5.0EPSS: 1%CPEs: 7EXPL: 1

Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228. Vulnerabilidad de atravesamiento de directorios en GoAhead Web Server 2.1 permite a atacantes remotos mediante una URL con una "/" (carácter barra) codificada (%5C) en una secuencia .. (punto punto) • https://www.exploit-db.com/exploits/21607 http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0013.html http://freecode.com/projects/embedthis-goahead-webserver/releases/343539 http://marc.info/?l=bugtraq&m=102631742711795&w=2 http://marc.info/?l=bugtraq&m=102709382714597&w=2 http://osvdb.org/81099 •