Shellinabox Project maintains a web-based terminal emulator that provides browser-accessible shell access, a narrow but strategically exposed product surface for remote system interaction. The vendor's disclosures center on control-flow and loop-handling weaknesses in its core terminal-access functionality, reflecting the parsing complexity inherent to terminal-session management. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shellinabox Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16789HIGH libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exp | Mar 21, 2019 | 7.5 | 27 | NO | NO |
CVE-2015-8400HIGH The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL. | Jan 12, 2016 | 7.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shellinabox Project.
Media articles that mention a CVE ID that affects a product developed by Shellinabox Project — matched by CVE ID, not by vendor name.