Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16789

Опубликовано: 21 мар. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:shellinabox_project:shellinabox:*:*:*:*:*:*:*:*
Версия до 2.20 (включая)

EPSS

Процентиль: 75%
0.00895
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.

CVSS3: 7.5
debian
почти 7 лет назад

libhttp/url.c in shellinabox through 2.20 has an implementation flaw i ...

CVSS3: 7.5
github
больше 3 лет назад

libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.

EPSS

Процентиль: 75%
0.00895
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-835