Boa Web Server 0.94.13 / 0.94.14 Authentication Bypass
Posted by deepcore on November 22, 2022 – 2:51 pm
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
Post a reply
You must be logged in to post a comment.