Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2021-33254

Disclosure Date: June 02, 2022 (last updated October 07, 2023)
An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.
Attacker Value
Unknown

CVE-2020-15689

Disclosure Date: July 13, 2020 (last updated February 21, 2025)
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.
Attacker Value
Unknown

CVE-2018-15504

Disclosure Date: August 18, 2018 (last updated November 27, 2024)
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Attacker Value
Unknown

CVE-2018-15505

Disclosure Date: August 18, 2018 (last updated November 27, 2024)
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
Attacker Value
Unknown

CVE-2018-8715

Disclosure Date: March 15, 2018 (last updated November 26, 2024)
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
0
Attacker Value
Unknown

CVE-2014-9708

Disclosure Date: March 31, 2015 (last updated October 05, 2023)
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
0
Attacker Value
Unknown

CVE-2007-3008

Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
0
Attacker Value
Unknown

CVE-2007-3009

Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
0
Attacker Value
Unknown

CVE-2004-2214

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
Attacker Value
Unknown

CVE-2004-2213

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
0