Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Webserver | Yaws | 1.50 (including) | 1.50 (including) |
| Webserver | Yaws | 1.51 (including) | 1.51 (including) |
| Webserver | Yaws | 1.52 (including) | 1.52 (including) |
| Webserver | Yaws | 1.53 (including) | 1.53 (including) |
| Webserver | Yaws | 1.54 (including) | 1.54 (including) |
| Webserver | Yaws | 1.55 (including) | 1.55 (including) |