Mbedthis Software Mbedthis Appweb Http Server vulnerabilities

5 known vulnerabilities affecting mbedthis_software/mbedthis_appweb_http_server.

Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2007-3008MEDIUMCVSS 4.3v2.0.0v2.0.1+8 more2007-06-04
CVE-2007-3008 [MEDIUM] CVE-2007-3008: Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably re Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
nvd
CVE-2007-3009MEDIUMCVSS 4.3PoCv2.0.5-42007-06-04
CVE-2007-3009 [MEDIUM] CVE-2007-3009: Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
nvd
CVE-2004-2315MEDIUMCVSS 5.0v1.0v1.0.12004-12-31
CVE-2004-2315 [MEDIUM] CVE-2004-2315: Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIONS request.
nvd
CVE-2004-2213MEDIUMCVSS 5.0v1.0v1.0.1+6 more2004-12-31
CVE-2004-2213 [MEDIUM] CVE-2004-2213: Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scrip Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
nvd
CVE-2004-2317MEDIUMCVSS 5.0v1.0v1.0.1+6 more2004-12-31
CVE-2004-2317 [MEDIUM] CVE-2004-2317: Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.
nvd