Vulnerability Description
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Steve Kneizys | Agora.Cgi | 3.2 |
References
- http://online.securityfocus.com/archive/1/252761PatchVendor Advisory
- http://www.iss.net/security_center/static/8011.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/3976
- http://online.securityfocus.com/archive/1/252761PatchVendor Advisory
- http://www.iss.net/security_center/static/8011.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/3976
FAQ
What is CVE-2002-0215?
CVE-2002-0215 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an erro...
How severe is CVE-2002-0215?
CVE-2002-0215 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0215?
Check the references section above for vendor advisories and patch information. Affected products include: Steve Kneizys Agora.Cgi.