MEDIUM · 5.0

CVE-2002-0680

Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely tha...

Vulnerability Description

Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Goahead SoftwareGoahead Webserver2.1.1
Orange SoftwareOrange Web Server2.1
Montavista SoftwareHard Hat Linux1.0

References

FAQ

What is CVE-2002-0680?

CVE-2002-0680 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely tha...

How severe is CVE-2002-0680?

CVE-2002-0680 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0680?

Check the references section above for vendor advisories and patch information. Affected products include: Goahead Software Goahead Webserver, Orange Software Orange Web Server, Montavista Software Hard Hat Linux.