Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2005-2008
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
Exploit prediction scoring system (EPSS) score
EPSS Score
0.005
EPSS Ranking
63.1%
CVSS Severity
CVSS v2 Score
5.0
References
http://marc.info/?l=bugtraq&m=111927717726371&w=2
http://secunia.com/advisories/15740
http://www.osvdb.org/17375
http://yaws.hyber.org/yaws-1.55_to_1.56.patch
http://marc.info/?l=bugtraq&m=111927717726371&w=2
http://secunia.com/advisories/15740
http://www.osvdb.org/17375
http://yaws.hyber.org/yaws-1.55_to_1.56.patch
Products affected by CVE-2005-2008
Yaws
»
Webserver
»
Version:
1.50
cpe:2.3:a:yaws:webserver:1.50
Yaws
»
Webserver
»
Version:
1.51
cpe:2.3:a:yaws:webserver:1.51
Yaws
»
Webserver
»
Version:
1.52
cpe:2.3:a:yaws:webserver:1.52
Yaws
»
Webserver
»
Version:
1.53
cpe:2.3:a:yaws:webserver:1.53
Yaws
»
Webserver
»
Version:
1.54
cpe:2.3:a:yaws:webserver:1.54
Yaws
»
Webserver
»
Version:
1.55
cpe:2.3:a:yaws:webserver:1.55
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved