← Back

Shellinabox Project

shellinabox_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Shellinabox
shellinabox

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Shellinabox Project
1Shellinabox
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an...Show more
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.Show less
2Fedoraproject
Shellinabox Project
2Fedora
Shellinabox
May 6, 2026
Jan 12, 2016
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.