ZeroHour

CVE-2020-24916

PoC ×3
CVSS 3.1
9.8 critical
EPSS
17%p97
Published
()
Modified
Description

CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

Vendors
yawscanonicaldebian
Products
yaws, ubuntu linux, debian linux
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.