Releases18
Frequency22 hours 20 minutes
Last Release
Stars57
The Boa web server. NOTE: Maintainers are not tracking this mirror. Do not make pull requests here, nor comment any commits, submit them usual way to bug tracker (https://www.gnupg.org/documentation/bts.html) or to the mailing list (https://www.gnupg.org/documentation/mailing-lists.html).

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 0.94.13, = 0.94.145.3 MEDIUM

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

= 0.94.14.219.8 CRITICAL

Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.

= 0.94.137.5 HIGH5 MEDIUM

Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.

<= 0.94.14.219.8 CRITICAL7.5 HIGH

Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.

<= 0.94.14.217.5 HIGH5 MEDIUM

Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.

= 0.94.14.217.5 HIGH7.8 HIGH

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.

= 0.92r5 MEDIUM

Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' and '.' characters.