5

CVE-2002-0770

Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Id SoftwareQuake 2i Server Version3.20
Id SoftwareQuake 2i Server Version3.21
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.53% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://online.securityfocus.com/archive/1/272548
http://www.iss.net/security_center/static/9095.php
Vendor Advisory
http://www.kb.cert.org/vuls/id/970915
US Government Resource
http://www.osvdb.org/11187
http://www.quakesrc.org/forum/topicDisplay.php?topicID=160
Vendor Advisory
http://www.securityfocus.com/bid/4744
Patch
Vendor Advisory