CVE-2019-16645 EXPLOIT
8.6
HIGH · CVSS 3.1 · EPSS 8.2% (pctl 95)
Patch early
A public exploit exists.
Description
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.
Scoring
| CVSS | 8.6 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
| EPSS | 8.18% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-09-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| embedthis | goahead |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GoAhead 2.5.0 - Host Header Injection | 2019-09-30 |
References
- http://packetstormsecurity.com/files/154652/GoAhead-2.5.0-Host-Header-Injection.html
- https://github.com/Ramikan/Vulnerabilities/blob/master/GoAhead%20Web%20server%20HTTP%20Header%20Injection
- http://packetstormsecurity.com/files/154652/GoAhead-2.5.0-Host-Header-Injection.html
- https://github.com/Ramikan/Vulnerabilities/blob/master/GoAhead%20Web%20server%20HTTP%20Header%20Injection
→ the Explorer · watch your stack · NVD