boa records
12 published records for vendor boa.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 8.3%
- Pre-auth RCE
- 1
- With a fix record
- 8.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-772 Missing Release of Resource after Effective Lifetime1
- CWE-863 Incorrect Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-248 Uncaught Exception1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2007-4915Weaponized | The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from enteboa · boa webserver · CWE-20 | Critical10.0 | — | 68.2% | Sep 17, 2007 |
51Plan | CVE-2017-9833Proof of concept | /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privboa · boa · CWE-22 | High7.5 | — | 68.5% | Jun 23, 2017 |
40Plan | CVE-2018-21027No exploit | Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.boa · boa · CWE-119 | Critical9.8 | — | 2.4% | Oct 11, 2019 |
39Monitor | CVE-2022-44117No exploit | Boa 0.94.14rc21 is vulnerable to SQL Injection via username.boa · boa · CWE-89 | Critical9.8 | — | 0.7% | Nov 23, 2022 |
34Monitor | CVE-2021-33558Proof of concept | Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, lboa · boa | High7.5 | — | 12.3% | May 27, 2021 |
31Monitor | CVE-2018-21028No exploit | Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.boa · boa · CWE-772 | High7.5 | — | 2.1% | Oct 11, 2019 |
30Monitor | CVE-2016-9564No exploit | Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with boa · boa · CWE-20 | High7.5 | — | 1.4% | Nov 30, 2016 |
30Monitor | CVE-2024-43367No exploit | Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objectsboa-dev · boa · CWE-248 | High7.5 | — | 0.6% | Aug 15, 2024 |
30Monitor | CVE-2024-47916No exploit | Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')boa web server · boa web server 0.94.14rc21 · CWE-22 | High7.5 | — | 0.5% | Nov 14, 2024 |
24Monitor | CVE-2009-4496Proof of concept | Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a windowboa · boa · CWE-20 | Medium5.0 | — | 12.3% | Jan 13, 2010 |
23Monitor | CVE-2000-0920Proof of concept | Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified ..boa · boa webserver | Medium5.0 | — | 8.4% | Dec 19, 2000 |
21Monitor | CVE-2022-45956No exploit | Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone tboa · boa · CWE-863 | Medium5.3 | — | 0.8% | Dec 12, 2022 |
- CVE-2007-491560This week
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from ente
CriticalCVSS 10.0WeaponizedEPSS 68%boa · boa webserverSep 17, 2007
- CVE-2017-983351Plan
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root priv
HighCVSS 7.5Proof of conceptEPSS 68%boa · boaJun 23, 2017
- CVE-2018-2102740Plan
Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.
CriticalCVSS 9.8No exploitEPSS 2%boa · boaOct 11, 2019
- CVE-2022-4411739Monitor
Boa 0.94.14rc21 is vulnerable to SQL Injection via username.
CriticalCVSS 9.8No exploitEPSS 1%boa · boaNov 23, 2022
- CVE-2021-3355834Monitor
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, l
HighCVSS 7.5Proof of conceptEPSS 12%boa · boaMay 27, 2021
- CVE-2018-2102831Monitor
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
HighCVSS 7.5No exploitEPSS 2%boa · boaOct 11, 2019
- CVE-2016-956430Monitor
Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with
HighCVSS 7.5No exploitEPSS 1%boa · boaNov 30, 2016
- CVE-2024-4336730Monitor
Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects
HighCVSS 7.5No exploitEPSS 1%boa-dev · boaAug 15, 2024
- CVE-2024-4791630Monitor
Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
HighCVSS 7.5No exploitEPSS 1%boa web server · boa web server 0.94.14rc21Nov 14, 2024
- CVE-2009-449624Monitor
Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window
MediumCVSS 5.0Proof of conceptEPSS 12%boa · boaJan 13, 2010
- CVE-2000-092023Monitor
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified ..
MediumCVSS 5.0Proof of conceptEPSS 8%boa · boa webserverDec 19, 2000
- CVE-2022-4595621Monitor
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone t
MediumCVSS 5.3No exploitEPSS 1%boa · boaDec 12, 2022