CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of...
Vulnerability Description
CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when compiled with the ME_GOAHEAD_JAVASCRIPT flag. This vulnerability allows a remote attacker with the privileges to modify JavaScript template (JST) files to trigger a crash and cause a Denial of Service (DoS) by providing malicious templates.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3186
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Diego Zaffaroni of Nozomi Networks found this bug during a security research activity.
More from EmbedThis
View All →Affected Vendor
EmbedThis
View all reports →