9.8
CVSSv3

CVE-2020-24916

Published: 09/09/2020 Updated: 06/12/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yaws yaws

debian debian linux 9.0

debian debian linux 10.0

canonical ubuntu linux 18.04

Vendor Advisories

Two vulnerabilities were discovered in yaws, a high performance HTTP 11 webserver written in Erlang CVE-2020-24379 The WebDAV implementation is prone to a XML External Entity (XXE) injection vulnerability CVE-2020-24916 The CGI implementation does not properly sanitize CGI requests allowing a remote attacker to execute arbitrary ...
CGI implementation in Yaws web server versions 181 to 207 is vulnerable to OS command injection ...

Exploits

Yaws versions 181 through 207 suffer from remote OS command injection and XML external entity injection vulnerabilities ...