Vulnerabilities > Embedthis > Goahead > 5.1.0

DATE CVE VULNERABILITY TITLE RISK
2022-01-25 CVE-2021-43298 Improper Restriction of Excessive Authentication Attempts vulnerability in Embedthis Goahead
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting.
network
low complexity
embedthis CWE-307
5.0
2021-10-14 CVE-2021-42342 Unrestricted Upload of File with Dangerous Type vulnerability in Embedthis Goahead
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5.
network
low complexity
embedthis CWE-434
7.5
2020-07-23 CVE-2020-15688 Authentication Bypass by Capture-replay vulnerability in Embedthis Goahead
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks.
network
low complexity
embedthis CWE-294
8.8