CRITICAL🇵🇱 Wersja polska

CVE-2021-42342

CVSS 9.8v3.1pub. 2021-10-14upd. 2024-11-21

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Embedthis Goahead

    APP
    Embedthis
    4.0.0 – 4.1.35.0.0 – 5.1.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-41615CRITICAL9.8PL ✓same product

GoAhead WebServer: niewystarczająca entropia nonce w uwierzytelnianiu HTTP Digest

CVE-2021-43298CRITICAL9.8PL ✓same product

Embedthis GoAhead: brute-force hasła HTTP Basic Auth przez timing attack

CVE-2019-5096CRITICAL9.8PL ✓same product

GoAhead Web Server: RCE przez use-after-free w obsłudze multipart/form-data

CVE-2017-1000471CRITICAL9.8PL ✓same product

NULL pointer dereference w obsłudze CGI serwera EmbedThis GoAhead 4.0.0

CVE-2017-5674CRITICAL9.8PL ✓same product

Ujawnienie hasła konfiguracyjnego w kamerach IP przez GoAhead