← Back

Goahead

goahead

10 CVEs • 3 products

Products (3)

Click to collapse
Toggle

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Goahead
1Wireless Ip Camera Wificam Firmware
Nov 21, 2024
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&por...Show more
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI.Show less
1Goahead
1Goahead Webserver
Apr 29, 2026
Dec 27, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
1Goahead
1Goahead Webserver
Apr 29, 2026
Nov 3, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the...Show more
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to goform/AddAccessLimit, related to addlimit.asp; or the (3) user (aka User ID) or (4) group parameter to goform/AddUser, related to adduser.asp.Show less
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path c...Show more
GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.Show less
2Goahead
Goahead Software
2Goahead Webserver
Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function.
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in GoAhead WebServer before 2.1.4 allows remote attackers to cause "incorrect behavior" via unknown "malicious code," related to incorrect use of the socketInputBuffered function by sockGen.c.
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GoAhead WebServer before 2.1.1 allows remote attackers to cause a denial of service (CPU consumption) by performing a socket disconnect to terminate a request before it has been fully processed by the server.
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header.
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data.
1Goahead
1Goahead Webserver
Apr 23, 2026
Feb 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-16...Show more
The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603.Show less