Sploitus

CVE-2014-9707

3 known exploits for CVE-2014-9707

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

Affected products
Goahead
Embedthis Goahead
= 3.0.0, 3.3.1, 3.3.2, 3.3.3, 3.3.4, 3.3.5, 3.3.6, 3.4.0
CVSS 2.0
7.5 HIGH
EPSS
28.2% (98th percentile)
Weakness
CWE-17
NVD status
Modified
Published
2015-03-31
CVE-2014-9707 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2014-9707

Proof-of-concept code and exploit modules indexed by Sploitus