Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2021-33254
Disclosure Date: June 02, 2022 (last updated October 07, 2023)
An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.
0
Attacker Value
Unknown
CVE-2020-15689
Disclosure Date: July 13, 2020 (last updated February 21, 2025)
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.
0
Attacker Value
Unknown
CVE-2018-15504
Disclosure Date: August 18, 2018 (last updated November 27, 2024)
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
0
Attacker Value
Unknown
CVE-2018-15505
Disclosure Date: August 18, 2018 (last updated November 27, 2024)
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
0
Attacker Value
Unknown
CVE-2018-8715
Disclosure Date: March 15, 2018 (last updated November 26, 2024)
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
0
Attacker Value
Unknown
CVE-2014-9708
Disclosure Date: March 31, 2015 (last updated October 05, 2023)
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
0
Attacker Value
Unknown
CVE-2007-3008
Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
0
Attacker Value
Unknown
CVE-2007-3009
Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
0
Attacker Value
Unknown
CVE-2004-2214
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
0
Attacker Value
Unknown
CVE-2004-2213
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
0