CVE-2020-24916
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
- Yaws
- ≤ 2.0.7
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 17.4% (97th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2020-09-09
CVE-2020-24916 at NVD
2 known exploits for CVE-2020-24916
Proof-of-concept code and exploit modules indexed by Sploitus