Advisory: CVE-2014-9707: GoAhead Web Server 3.0.0 – 3.4.1

Posted by Matthew Daley on Mar 28

Affected software: GoAhead Web Server
Affected versions: 3.0.0 – 3.4.1 (3.x.x series before 3.4.2)
CVE ID: CVE-2014-9707

Description: The server incorrectly normalizes HTTP request URIs that
contain path segments that start with a “.” but are not entirely equal
to “.” or “..” (eg. “.x”). By sending a request with a URI that
contains these incorrectly handled segments, it is possible for remote
attackers to…

Leave a Reply