Vulnerabilities (CVE)

Filtered by vendor Boa Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-33558 1 Boa 1 Boa 2021-06-04 5.0 MEDIUM 7.5 HIGH
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js.
CVE-2018-21028 1 Boa 1 Boa 2019-10-16 5.0 MEDIUM 7.5 HIGH
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
CVE-2017-9833 1 Boa 1 Boa 2019-04-18 7.8 HIGH 7.5 HIGH
/cgi-bin/wapopen in BOA Webserver 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges.
CVE-2016-9564 1 Boa 1 Boa 2016-12-03 5.0 MEDIUM 7.5 HIGH
Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' and '.' characters.