Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-5674

Опубликовано: 13 мар. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:embedthis:goahead:-:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00808
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password.

EPSS

Процентиль: 74%
0.00808
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200