7.5

CVE-2014-9707

Exploit

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EmbedthisGoahead Version3.0.0
EmbedthisGoahead Version3.3.1
EmbedthisGoahead Version3.3.2
EmbedthisGoahead Version3.3.3
EmbedthisGoahead Version3.3.4
EmbedthisGoahead Version3.3.5
EmbedthisGoahead Version3.3.6
EmbedthisGoahead Version3.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 66.12% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P