Directory Traversal Vulnerability in EmbedThis GoAhead Web Server 3.0.0 - 3.4.1
CVE-2014-9707

Currently unrated

Key Information:

Vendor

Embedthis

Status
Vendor
CVE Published:
31 March 2015

What is CVE-2014-9707?

The EmbedThis GoAhead Web Server versions 3.0.0 through 3.4.1 has a vulnerability that allows for improper handling of path segments beginning with a dot (.) character. This weakness can lead to directory traversal attacks, potentially enabling remote attackers to access unauthorized files on the server. Additionally, it exposes users to denial of service scenarios due to a heap-based buffer overflow, which can cause the server to crash and, in certain situations, may allow the execution of arbitrary code through specially crafted URIs.

References

EPSS Score

66% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.