VYPR

Webserver

by Yaws

CVEs (3)

  • CVE-2020-24916CriSep 9, 2020
    risk 0.65cvss 9.8epss 0.17

    CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

  • CVE-2020-24379CriSep 9, 2020
    risk 0.64cvss 9.8epss 0.03

    WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

  • CVE-2005-2008Jun 17, 2005
    risk 0.00cvss —epss 0.01

    Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).