Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.
| Software | From | Fixed in |
|---|---|---|
| goahead_software / goahead_webserver | 2.1.1 | 2.1.1.x |
| goahead_software / goahead_webserver | 2.1.5 | 2.1.5.x |
| goahead_software / goahead_webserver | 2.1.2 | 2.1.2.x |
| goahead_software / goahead_webserver | 2.1.4 | 2.1.4.x |
| goahead_software / goahead_webserver | 2.1.3 | 2.1.3.x |