CVE-2018-15505

Severity
7.5HIGH
EPSS
0.2%
top 62.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateMay 14

Description

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDembedthis/appweb< 7.0.2
NVDembedthis/goahead< 4.0.1
NVDjuniper/junos12 versions+11

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2g98-g66w-rvrw: An issue was discovered in Embedthis GoAhead before 42022-05-14
CVEList
CVE-2018-15505: An issue was discovered in Embedthis GoAhead before 42018-08-18
CVE-2018-15505 (HIGH CVSS 7.5) | An issue was discovered in Embedthi | cvebase.io