// For flags

CVE-2002-0680

GoAhead Web Server 2.1.x - URL Encoded Slash Directory Traversal

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.

Vulnerabilidad de atravesamiento de directorios en GoAhead Web Server 2.1 permite a atacantes remotos mediante una URL con una "/" (carácter barra) codificada (%5C) en una secuencia .. (punto punto)

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2002-07-10 CVE Reserved
  • 2002-07-10 First Exploit
  • 2002-07-12 CVE Published
  • 2024-06-11 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Goahead Software
Search vendor "Goahead Software"
Goahead Webserver
Search vendor "Goahead Software" for product "Goahead Webserver"
2.1.1
Search vendor "Goahead Software" for product "Goahead Webserver" and version "2.1.1"
-
Affected
Goahead Software
Search vendor "Goahead Software"
Goahead Webserver
Search vendor "Goahead Software" for product "Goahead Webserver"
2.1.2
Search vendor "Goahead Software" for product "Goahead Webserver" and version "2.1.2"
-
Affected
Goahead Software
Search vendor "Goahead Software"
Goahead Webserver
Search vendor "Goahead Software" for product "Goahead Webserver"
2.1.3
Search vendor "Goahead Software" for product "Goahead Webserver" and version "2.1.3"
-
Affected
Goahead Software
Search vendor "Goahead Software"
Goahead Webserver
Search vendor "Goahead Software" for product "Goahead Webserver"
2.1.4
Search vendor "Goahead Software" for product "Goahead Webserver" and version "2.1.4"
-
Affected
Goahead Software
Search vendor "Goahead Software"
Goahead Webserver
Search vendor "Goahead Software" for product "Goahead Webserver"
2.1.5
Search vendor "Goahead Software" for product "Goahead Webserver" and version "2.1.5"
-
Affected
Orange Software
Search vendor "Orange Software"
Orange Web Server
Search vendor "Orange Software" for product "Orange Web Server"
2.1
Search vendor "Orange Software" for product "Orange Web Server" and version "2.1"
-
Affected
Montavista Software
Search vendor "Montavista Software"
Hard Hat Linux
Search vendor "Montavista Software" for product "Hard Hat Linux"
1.0
Search vendor "Montavista Software" for product "Hard Hat Linux" and version "1.0"
-
Affected