Home/Product/boa
Product

boa

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-45956
all versions
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing
5.3MEDIUM
CVE-2022-44117
all versions
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not
9.8CRITICAL
CVE-2021-33558
all versions
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js
7.5HIGH
CVE-2018-21028
<= 0.94.14.21
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
7.5HIGH
CVE-2018-21027
<= 0.94.14.21
Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.
9.8CRITICAL
CVE-2017-9833
all versions
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with
7.5HIGH
CVE-2016-9564
all versions
Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long
7.5HIGH
CVE-2009-4496
all versions
Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modif
CVE-2007-4915
all versions
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes
CVE-2000-0920
<= 0.94.8.2
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a mod
threatengine.sh