Vulnerabilities > CVE-2002-0680 - Directory Traversal vulnerability in GoAhead WebServer

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
goahead-software
orange-software
montavista-software
exploit available

Summary

Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.

Exploit-Db

descriptionGoAhead WebServer 2.1.x URL Encoded Slash Directory Traversal Vulnerability. CVE-2002-0680. Remote exploit for windows platform
idEDB-ID:21607
last seen2016-02-02
modified2002-07-10
published2002-07-10
reporterMatt Moore
sourcehttps://www.exploit-db.com/download/21607/
titleGoAhead WebServer 2.1.x URL Encoded Slash Directory Traversal Vulnerability