MidnightBSD

Advisories for shellinabox_project

CVE-2015-8400 MEDIUM

The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
fedoraproject fedora 23
fedoraproject fedora 22
shellinabox_project shellinabox *