Vulnerability record · CVE-2018-16789 · published 21 March 2019
CVE-2018-16789: Shellinabox project shellinabox vulnerability
Shellinabox Project · Shellinabox
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
Description
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/149978/Shell-In-A-Box-2.2.0-Denial-Of-Service.html | ExploitPatchThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2018/Oct/50 | ExploitMailing ListPatchThird Party Advisory |
| https://code.google.com/archive/p/shellinabox/issues | Third Party Advisory |
| https://github.com/shellinabox/shellinabox/commit/4f0ecc31ac6f985e0dd3f5a52cbfc0e9251f6361 | PatchThird Party Advisory |
| http://packetstormsecurity.com/files/149978/Shell-In-A-Box-2.2.0-Denial-Of-Service.html | ExploitPatchThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2018/Oct/50 | ExploitMailing ListPatchThird Party Advisory |
| https://code.google.com/archive/p/shellinabox/issues | Third Party Advisory |
| https://github.com/shellinabox/shellinabox/commit/4f0ecc31ac6f985e0dd3f5a52cbfc0e9251f6361 | PatchThird Party Advisory |
Track CVE-2018-16789 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-16789), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.