Записи boa
12 опубликованных записей вендора boa.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 8,3 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 8,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-772 Missing Release of Resource after Effective Lifetime1
- CWE-863 Incorrect Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-248 Uncaught Exception1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2007-4915Готовый эксплойт | The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from enteboa · boa webserver · CWE-20 | Критическая10,0 | — | 68,2 % | 17 сент. 2007 г. |
51В плане | CVE-2017-9833Proof of concept | /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privboa · boa · CWE-22 | Высокая7,5 | — | 68,5 % | 23 июн. 2017 г. |
40В плане | CVE-2018-21027Эксплойта нет | Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.boa · boa · CWE-119 | Критическая9,8 | — | 2,4 % | 11 окт. 2019 г. |
39Наблюдать | CVE-2022-44117Эксплойта нет | Boa 0.94.14rc21 is vulnerable to SQL Injection via username.boa · boa · CWE-89 | Критическая9,8 | — | 0,7 % | 23 нояб. 2022 г. |
34Наблюдать | CVE-2021-33558Proof of concept | Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, lboa · boa | Высокая7,5 | — | 12,3 % | 27 мая 2021 г. |
31Наблюдать | CVE-2018-21028Эксплойта нет | Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.boa · boa · CWE-772 | Высокая7,5 | — | 2,1 % | 11 окт. 2019 г. |
30Наблюдать | CVE-2016-9564Эксплойта нет | Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with boa · boa · CWE-20 | Высокая7,5 | — | 1,4 % | 30 нояб. 2016 г. |
30Наблюдать | CVE-2024-43367Эксплойта нет | Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objectsboa-dev · boa · CWE-248 | Высокая7,5 | — | 0,6 % | 15 авг. 2024 г. |
30Наблюдать | CVE-2024-47916Эксплойта нет | Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')boa web server · boa web server 0.94.14rc21 · CWE-22 | Высокая7,5 | — | 0,5 % | 14 нояб. 2024 г. |
24Наблюдать | CVE-2009-4496Proof of concept | Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a windowboa · boa · CWE-20 | Средняя5,0 | — | 12,3 % | 13 янв. 2010 г. |
23Наблюдать | CVE-2000-0920Proof of concept | Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified ..boa · boa webserver | Средняя5,0 | — | 8,4 % | 19 дек. 2000 г. |
21Наблюдать | CVE-2022-45956Эксплойта нет | Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone tboa · boa · CWE-863 | Средняя5,3 | — | 0,8 % | 12 дек. 2022 г. |
- CVE-2007-491560На этой неделе
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from ente
КритическаяCVSS 10,0Готовый эксплойтEPSS 68 %boa · boa webserver17 сент. 2007 г.
- CVE-2017-983351В плане
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root priv
ВысокаяCVSS 7,5Proof of conceptEPSS 68 %boa · boa23 июн. 2017 г.
- CVE-2018-2102740В плане
Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %boa · boa11 окт. 2019 г.
- CVE-2022-4411739Наблюдать
Boa 0.94.14rc21 is vulnerable to SQL Injection via username.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %boa · boa23 нояб. 2022 г.
- CVE-2021-3355834Наблюдать
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, l
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %boa · boa27 мая 2021 г.
- CVE-2018-2102831Наблюдать
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %boa · boa11 окт. 2019 г.
- CVE-2016-956430Наблюдать
Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %boa · boa30 нояб. 2016 г.
- CVE-2024-4336730Наблюдать
Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %boa-dev · boa15 авг. 2024 г.
- CVE-2024-4791630Наблюдать
Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %boa web server · boa web server 0.94.14rc2114 нояб. 2024 г.
- CVE-2009-449624Наблюдать
Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window
СредняяCVSS 5,0Proof of conceptEPSS 12 %boa · boa13 янв. 2010 г.
- CVE-2000-092023Наблюдать
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified ..
СредняяCVSS 5,0Proof of conceptEPSS 8 %boa · boa webserver19 дек. 2000 г.
- CVE-2022-4595621Наблюдать
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone t
СредняяCVSS 5,3Эксплойта нетEPSS 1 %boa · boa12 дек. 2022 г.