5
CVSSv2

CVE-2019-16645

Published: 20/09/2019 Updated: 24/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

embedthis goahead 2.5.0

Exploits

# Exploit Title: GoAhead Web server HTTP Header Injection # Shodan Query: Server: Goahead # Discovered Date: 05/07/2019 # Exploit Author: Ramikan # Vendor Homepage: wwwembedthiscom/goahead/ # Affected Version: 250 may be others # Tested On Version: 250 in Cisco Switches and Net Gear routers # Vendor Fix: N/A # CVE : N/A # CVSS v3: ...