Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-20798

An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.3%
CVSS Severity
CVSS v3 Score 8.4
CVSS v2 Score 6.0
Products affected by CVE-2019-20798


Contact Us

Shodan ® - All rights reserved