Webserver
by Yaws
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24916 | Cri | 0.65 | 9.8 | 0.17 | Sep 9, 2020 | CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection. | ||
| CVE-2020-24379 | Cri | 0.64 | 9.8 | 0.03 | Sep 9, 2020 | WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. | ||
| CVE-2005-2008 | 0.00 | — | 0.01 | Jun 17, 2005 | Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null). |
- risk 0.65cvss 9.8epss 0.17
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
- risk 0.64cvss 9.8epss 0.03
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
- CVE-2005-2008Jun 17, 2005risk 0.00cvss —epss 0.01
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).