Skip to main content
Security Advisory

GoAhead Web Server

Risk Information

Limited Threat

CVE ID

CVE-2011-4273

CVE-2009-5111

CVE-2003-1569

CVE-2003-1568

CVE-2002-2431

CVE-2002-2430

CVE-2002-2429

CVE-2002-2428

CVE-2002-2427

Vunerability Type

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Resource Exhaustion

Memory Corruption

Improper Input Validation

Uncaught Exception

Denial of Service CPU Consumption

Denial of Service Daemon Crash

Denial of Service Pointer Dereference and Daemon Crash

Unauthorized Access and Authentication Bypass

CVSS3 Score

9.6

7.5

7.5

7.5

7.5

7.5

7.5

7.5

9.8

CVSSv3 Vector

AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affecting

  • GoAhead Web Server: prior to v4.0.1.
  • Mitigation

    Update to a patched version, v4.0.1 or later.

    10/18/2017