CVE-2025-56498
- EPSS 1.41%
- Veröffentlicht 03.09.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 15:58:46
An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submits user input to the /boaform/formPing6 endpoint via the pingAddr parameter, which is not properly sa...
CVE-2024-43367
- EPSS 0.22%
- Veröffentlicht 15.08.2024 21:15:17
- Zuletzt bearbeitet 19.08.2024 13:00:23
Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0.19.0, a wrong assumption made when handling ECMAScript's `AsyncGenerator` operations can cause an uncaught exception on certain s...
CVE-2022-45956
- EPSS 0.35%
- Veröffentlicht 12.12.2022 15:15:10
- Zuletzt bearbeitet 22.04.2025 20:15:26
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
CVE-2022-44117
- EPSS 0.32%
- Veröffentlicht 23.11.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:27:38
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.
CVE-2021-33558
- EPSS 93.14%
- Veröffentlicht 27.05.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:05
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site...
CVE-2018-21027
- EPSS 0.75%
- Veröffentlicht 11.10.2019 20:15:16
- Zuletzt bearbeitet 21.11.2024 04:02:43
Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.
CVE-2018-21028
- EPSS 0.58%
- Veröffentlicht 11.10.2019 20:15:16
- Zuletzt bearbeitet 21.11.2024 04:02:43
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
CVE-2017-9833
- EPSS 90.08%
- Veröffentlicht 24.06.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on o...
CVE-2016-9564
- EPSS 0.62%
- Veröffentlicht 30.11.2016 11:59:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' and '.' characters.
- EPSS 10.05%
- Veröffentlicht 13.01.2010 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape ...