CRITICAL🇵🇱 Wersja polska

CVE-2019-5096

CVSS 9.8v3.1pub. 2019-12-03upd. 2024-11-21

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Embedthis Goahead

    APP
    Embedthis
    3.6.54.1.15.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2021-41615CRITICAL9.8PL ✓same product

GoAhead WebServer: niewystarczająca entropia nonce w uwierzytelnianiu HTTP Digest

CVE-2021-43298CRITICAL9.8PL ✓same product

Embedthis GoAhead: brute-force hasła HTTP Basic Auth przez timing attack

CVE-2021-42342CRITICAL9.8PL ✓same product

GoAhead: tunelowanie zmiennych środowiskowych do skryptów CGI przez upload pliku

CVE-2017-1000471CRITICAL9.8PL ✓same product

NULL pointer dereference w obsłudze CGI serwera EmbedThis GoAhead 4.0.0

CVE-2017-5674CRITICAL9.8PL ✓same product

Ujawnienie hasła konfiguracyjnego w kamerach IP przez GoAhead