5

CVE-2002-1603

Exploit
GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.67% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://aluigi.altervista.org/adv/goahead-adv3.txt
Vendor Advisory
Exploit
http://data.goahead.com/Software/Webserver/2.1.8/release.htm#bug-with-urls-like-asp
http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729
http://secunia.com/advisories/7741
http://securitytracker.com/id?1005820
Exploit
http://www.kb.cert.org/vuls/id/124059
US Government Resource
http://www.kb.cert.org/vuls/id/975041
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/RGII-7MWKZ3
http://www.osvdb.org/13295
http://www.procheckup.com/PDFs/ProCheckUp_Vulns_2002.pdf
http://www.procheckup.com/security_info/vuln_pr0213.html
http://www.securityfocus.com/bid/9239
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/10885