V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2011-2900
CVE
HighConfirmedExploit available

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded…

CVSS
7.5
High
EPSS
0.54
p98
Published
2011-01-01
Updated
2011-01-01
Description

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

Tags · CWE
RCE
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
ShttpdMongooseYasslews
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2011-01-01
Published
2011-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.537 · p98
Known exploited (KEV)
No
Known exploits — Сканер-ВС
17658
exploitdb · https://www.exploit-db.com/exploits/17658
Enterprise
17669
exploitdb · https://www.exploit-db.com/exploits/17669
Enterprise
Affected software
ProductVendorStatus
mongoose*Tracked
shttpd*Tracked
yasslews*Tracked
Source databases
CVE