← Back to CVEs
CVE-2017-17562
HIGHCISA KEV8.1
Description
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.
CVE Details
CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published12/12/2017
Last Modified4/21/2026
Sourcekev
Honeypot Sightings0
CISA KEV
VendorEmbedthis
ProductGoAhead
Vulnerability NameEmbedthis GoAhead Remote Code Execution Vulnerability
KEV Date Added2021-12-10
Remediation Due Date2022-06-10
Ransomware UseUnknown
Affected Products
embedthis:goaheadoracle:integrated_lights_out_manager
References
http://www.securitytracker.com/id/1040702(cve@mitre.org)
https://github.com/embedthis/goahead/issues/249(cve@mitre.org)
https://www.elttam.com.au/blog/goahead/(cve@mitre.org)
https://www.exploit-db.com/exploits/43360/(cve@mitre.org)
https://www.exploit-db.com/exploits/43877/(cve@mitre.org)
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1040702(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/elttam/advisories/tree/master/CVE-2017-17562(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/embedthis/goahead/commit/6f786c123196eb622625a920d54048629a7caa74(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/embedthis/goahead/issues/249(af854a3a-2127-422b-91ae-364da2661108)
https://www.elttam.com.au/blog/goahead/(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/43360/(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/43877/(af854a3a-2127-422b-91ae-364da2661108)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-17562(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.