An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEmbedthis Goahead
APPEmbedthis4.0.0 – 4.1.35.0.0 – 5.1.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-41615CRITICAL9.8PL ✓same product
GoAhead WebServer: niewystarczająca entropia nonce w uwierzytelnianiu HTTP Digest
CVE-2021-43298CRITICAL9.8PL ✓same product
Embedthis GoAhead: brute-force hasła HTTP Basic Auth przez timing attack
CVE-2019-5096CRITICAL9.8PL ✓same product
GoAhead Web Server: RCE przez use-after-free w obsłudze multipart/form-data
CVE-2017-1000471CRITICAL9.8PL ✓same product
NULL pointer dereference w obsłudze CGI serwera EmbedThis GoAhead 4.0.0
CVE-2017-5674CRITICAL9.8PL ✓same product
Ujawnienie hasła konfiguracyjnego w kamerach IP przez GoAhead