Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-24916
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.39
EPSS Ranking
97.1%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
10.0
References
https://github.com/erlyaws/yaws/commits/master
https://github.com/vulnbe/poc-yaws-cgi-shell-injection
https://lists.debian.org/debian-lts-announce/2020/09/msg00022.html
https://packetstormsecurity.com/files/159106/Yaws-2.0.7-XML-Injection-Command-Injection.html
https://usn.ubuntu.com/4569-1/
https://vuln.be/post/yaws-xxe-and-shell-injections/
https://www.debian.org/security/2020/dsa-4773
https://github.com/erlyaws/yaws/commits/master
https://github.com/vulnbe/poc-yaws-cgi-shell-injection
https://lists.debian.org/debian-lts-announce/2020/09/msg00022.html
https://packetstormsecurity.com/files/159106/Yaws-2.0.7-XML-Injection-Command-Injection.html
https://usn.ubuntu.com/4569-1/
https://vuln.be/post/yaws-xxe-and-shell-injections/
https://www.debian.org/security/2020/dsa-4773
Products affected by CVE-2020-24916
Yaws
»
Yaws
»
Version:
1.81
cpe:2.3:a:yaws:yaws:1.81
Yaws
»
Yaws
»
Version:
1.82
cpe:2.3:a:yaws:yaws:1.82
Yaws
»
Yaws
»
Version:
1.83
cpe:2.3:a:yaws:yaws:1.83
Yaws
»
Yaws
»
Version:
1.84
cpe:2.3:a:yaws:yaws:1.84
Yaws
»
Yaws
»
Version:
1.85
cpe:2.3:a:yaws:yaws:1.85
Yaws
»
Yaws
»
Version:
1.86
cpe:2.3:a:yaws:yaws:1.86
Yaws
»
Yaws
»
Version:
1.87
cpe:2.3:a:yaws:yaws:1.87
Yaws
»
Yaws
»
Version:
1.88
cpe:2.3:a:yaws:yaws:1.88
Yaws
»
Yaws
»
Version:
1.89
cpe:2.3:a:yaws:yaws:1.89
Yaws
»
Yaws
»
Version:
1.90
cpe:2.3:a:yaws:yaws:1.90
Yaws
»
Yaws
»
Version:
1.91
cpe:2.3:a:yaws:yaws:1.91
Yaws
»
Yaws
»
Version:
1.92
cpe:2.3:a:yaws:yaws:1.92
Yaws
»
Yaws
»
Version:
1.93
cpe:2.3:a:yaws:yaws:1.93
Yaws
»
Yaws
»
Version:
1.94
cpe:2.3:a:yaws:yaws:1.94
Yaws
»
Yaws
»
Version:
1.95
cpe:2.3:a:yaws:yaws:1.95
Yaws
»
Yaws
»
Version:
1.96
cpe:2.3:a:yaws:yaws:1.96
Yaws
»
Yaws
»
Version:
1.97
cpe:2.3:a:yaws:yaws:1.97
Yaws
»
Yaws
»
Version:
1.98
cpe:2.3:a:yaws:yaws:1.98
Yaws
»
Yaws
»
Version:
1.99
cpe:2.3:a:yaws:yaws:1.99
Yaws
»
Yaws
»
Version:
2.0
cpe:2.3:a:yaws:yaws:2.0
Yaws
»
Yaws
»
Version:
2.0.1
cpe:2.3:a:yaws:yaws:2.0.1
Yaws
»
Yaws
»
Version:
2.0.2
cpe:2.3:a:yaws:yaws:2.0.2
Yaws
»
Yaws
»
Version:
2.0.3
cpe:2.3:a:yaws:yaws:2.0.3
Yaws
»
Yaws
»
Version:
2.0.4
cpe:2.3:a:yaws:yaws:2.0.4
Yaws
»
Yaws
»
Version:
2.0.5
cpe:2.3:a:yaws:yaws:2.0.5
Yaws
»
Yaws
»
Version:
2.0.6
cpe:2.3:a:yaws:yaws:2.0.6
Yaws
»
Yaws
»
Version:
2.0.7
cpe:2.3:a:yaws:yaws:2.0.7
Canonical
»
Ubuntu Linux
»
Version:
18.04
cpe:2.3:o:canonical:ubuntu_linux:18.04
Debian
»
Debian Linux
»
Version:
10.0
cpe:2.3:o:debian:debian_linux:10.0
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved