Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-2891

An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send this HTTP request over the network to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.029
EPSS Ranking 86.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2017-2891


Contact Us

Shodan ® - All rights reserved