7.5

CVE-2014-9707

Exploit

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

Data is provided by the National Vulnerability Database (NVD)
EmbedthisGoahead Version3.0.0
EmbedthisGoahead Version3.3.1
EmbedthisGoahead Version3.3.2
EmbedthisGoahead Version3.3.3
EmbedthisGoahead Version3.3.4
EmbedthisGoahead Version3.3.5
EmbedthisGoahead Version3.3.6
EmbedthisGoahead Version3.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 66.12% 0.983
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P