Unrated severityNVD Advisory· Published Mar 31, 2015· Updated May 6, 2026
CVE-2014-9707
CVE-2014-9707
Description
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.
Affected products
8cpe:2.3:a:embedthis:goahead:3.0.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:embedthis:goahead:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:embedthis:goahead:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:embedthis:goahead:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:embedthis:goahead:3.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:embedthis:goahead:3.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:embedthis:goahead:3.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:embedthis:goahead:3.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:embedthis:goahead:3.4.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- packetstormsecurity.com/files/131156/GoAhead-3.4.1-Heap-Overflow-Traversal.htmlnvdExploit
- seclists.org/fulldisclosure/2015/Mar/157nvdExploit
- www.securityfocus.com/archive/1/535027/100/0/threadednvd
- www.securitytracker.com/id/1032208nvd
- github.com/embedthis/goahead/commit/eed4a7d177bf94a54c7b06ccce88507fbd76fb77nvd
- github.com/embedthis/goahead/issues/106nvd
News mentions
0No linked articles in our index yet.