Skip to main content

CVE-2017-17562

8.1
HIGHCVSS v3.1 Base Score
94.27%
HIGH RiskEPSS (100th percentile)
KEV
NVD-CWE-noinfo

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

Published: 12/12/2017
Modified: 4/21/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Embedthis GoAhead Remote Code Execution Vulnerability

Vendor / Product:

Embedthis GoAhead

Required Action:

Apply updates per vendor instructions.

Due Date: 6/10/2022(OVERDUE)
Added to KEV:

12/10/2021

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2017-17562

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

94.27%HIGH Exploitation Risk
100th percentile

This vulnerability has a 94.27% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities