Sploitus

CVE-2018-15505

No indexed exploits for CVE-2018-15505 yet

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.

Affected products
Appweb, Goahead
Embedthis Appweb
< 7.0.2
Embedthis Goahead
< 4.0.1
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
2.2% (81th percentile)
Weakness
CWE-476
NVD status
Modified
Published
2018-08-18
CVE-2018-15505 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2018-15505 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2018-15505 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.