ZeroHour

CVE-2018-15504

PoC ×2
CVSS 3.1
7.5 high
EPSS
3%p85
Published
()
Modified
Description

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.

Vendors
embedthisjuniper
Products
appweb, goahead, junos
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.