← Vulnerability feed

Vulnerability record · CVE-2014-9707 · published 31 March 2015

CVE-2014-9707: Embedthis goahead vulnerability

Embedthis · Goahead

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

7.5 CVSS 2.0 High EPSS 28% · top 1.9% CWE-17 · CWE-17
7.5CVSS 2.0 base score
28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9707 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-17562Embedthis GoAhead CGI environment variable injection enables remote code executionEmbedthis GoAhead before 3.6.5 initializes the environment of forked CGI scripts using untrusted HTTP request parameters in cgiHandler in cgi.c. When…KEVEPSS 96%analysed9.8CVE-2021-41615Embedthis goahead vulnerabilitywebsda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise valu…EPSS 1.4%9.8CVE-2021-43298Embedthis goahead improper restriction of authentication attempts vulnerabilityThe code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This me…EPSS 2.3%9.8CVE-2021-42342GoAhead file upload filter allows environment variable injection into CGI scriptsGoAhead 4.x and 5.x before 5.1.5 fail to prefix user form variables with the CGI prefix in the file upload filter, letting untrusted environment vari…EPSS 59%analysed9.8CVE-2019-5096GoAhead web server use-after-free in multipart/form-data handlingGoAhead versions 5.0.1, 4.1.1 and 3.6.5 contain a use-after-free when processing multipart/form-data requests. A crafted HTTP request corrupts heap s…EPSS 67%analysed9.8CVE-2017-1000471Embedthis goahead null pointer dereference vulnerabilityEmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of …EPSS 8.6%9.8CVE-2017-5674Embedthis goahead information exposure vulnerabilityA vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft …EPSS 22%8.8CVE-2020-15688Embedthis goahead authentication bypass by capture-replay vulnerabilityThe HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthentica…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2014-9707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.