5

CVE-2002-2094

Exploit
Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root's parent, which generates a 403 error message if the parent is incorrect, but a normal response if the parent is correct.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JoetestaHellbent Version0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.79% 0.846
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

http://archives.neohapsis.com/archives/bugtraq/2002-01/0228.html
Patch
Vendor Advisory
Exploit
Broken Link
http://www.iss.net/security_center/static/7930.php
Patch
Broken Link
http://www.securityfocus.com/bid/3908
Patch
Third Party Advisory
Broken Link
VDB Entry