694
VMScore

CVE-2018-16789

Published: 21/03/2019 Updated: 24/08/2020
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

libhttp/url.c in shellinabox up to and including 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shellinabox project shellinabox

Mailing Lists

Product: Shell In A Box (aka shellinabox, shellinaboxd) "Shell In A Box implements a web server that can export arbitrary command line tools to a web based terminal emulator This emulator is accessible to any JavaScript and CSS enabled web browser and does not require any additional browser plugins " Most official-ish site: githubcom/sh ...