Description
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.
Related CPE's
a
embedthis
goahead
2
References
https://github.com/embedthis/goahead/issues/305
Third Party Advisory
https://github.com/embedthis/goahead/issues/305
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-14T04:15:07.037Z
4 years agoLast modified
2024-11-21T05:27:38.790Z
1 year ago