Executive brief
Embedthis GoAhead allows remote code execution when CGI is enabled and a CGI program is dynamically linked. The vulnerability occurs because the cgiHandler function initializes the environment of forked CGI scripts using untrusted HTTP request parameters, allowing attackers to inject environment variables like LD_PRELOAD.
Affected products
- Embedthis GoAhead before 3.6.5
- Oracle Integrated Lights Out Manager 3.0, 4.0
Timeline
- 2017-12-12: disclosed: Initial vulnerability disclosure date based on CVE ID year and external references.
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.