{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2017-17562/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2017-17562/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2017-17562/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2017-17562/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2017-17562/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2017-17562"},"sightings":{"href":"/api/v1/sightings/cve-2017-17562"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2017/CVE-2017-17562.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2017-17562\n\ninfo:\n  name: Embedthis GoAhead <3.6.5 - Remote Code Execution\n  author: geeknik\n  severity: high\n  description: |\n    description: Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.\n  impact: |\n    Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the target system.\n  remediation: |\n    Upgrade to Embedthis GoAhead version 3.6.5 or later to mitigate this vulnerability.\n  reference:\n    - https://www.elttam.com/blog/goahead/\n    - https://github.com/ivanitlearning/CVE-2017-17562\n    - https://github.com/vulhub/vulhub/tree/master/goahead/CVE-2017-17562\n    - https://github.com/embedthis/goahead/issues/249\n    - https://nvd.nist.gov/vuln/detail/CVE-2017-17562\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 8.1\n    cve-id: CVE-2017-17562\n    cwe-id: CWE-20\n    epss-score: 0.96262\n    epss-percentile: 0.99877\n    cpe: cpe:2.3:a:embedthis:goahead:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 65\n    vendor: embedthis\n    product: goahead\n    shodan-query: cpe:\"cpe:2.3:a:embedthis:goahead\"\n  tags: cve,cve2017,rce,goahead,fuzz,kev,vulhub,embedthis,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /cgi-bin/{{endpoint}}?LD_DEBUG=help HTTP/1.1\n        Host: {{Hostname}}\n        Accept: */*\n\n    payloads:\n      endpoint:\n        - admin\n        - apply\n        - non-CA-rev\n        - cgitest\n        - checkCookie\n        - check_user\n        - chn/liveView\n        - cht/liveView\n        - cnswebserver\n        - config\n        - configure/set_link_neg\n        - configure/swports_adjust\n        - eng/liveView\n        - firmware\n        - getCheckCode\n        - get_status\n        - getmac\n        - getparam\n        - guest/Login\n        - home\n        - htmlmgr\n        - index\n        - index/login\n        - jscript\n        - kvm\n        - liveView\n        - login\n        - login.asp\n        - login/login\n        - login/login-page\n        - login_mgr\n        - luci\n        - main\n        - main-cgi\n        - manage/login\n        - menu\n        - mlogin\n        - netbinary\n        - nobody/Captcha\n        - nobody/VerifyCode\n        - normal_userLogin\n        - otgw\n        - page\n        - rulectl\n        - service\n        - set_new_config\n        - sl_webviewer\n        - ssi\n        - status\n        - sysconf\n        - systemutil\n        - t/out\n        - top\n        - unauth\n        - upload\n        - variable\n        - wanstatu\n        - webcm\n        - webmain\n        - webproc\n        - webscr\n        - webviewLogin\n        - webviewLogin_m64\n        - webviewer\n        - welcome\n    stop-at-first-match: true\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        words:\n          - \"environment variable\"\n          - \"display library search paths\"\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a0047304502203a66745f524a137bacbb4a09e0fd93d1cc3c43d1cea6296ca628074b911d4a39022100974b286f18ad672998ee14c0f0f42bccfab512fcc40252e3fd7e88a8d22c359d:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2017-17562"}