Moderate

CVE-2002-1603 - Unspecified vulnerability in Goahead Software Goahead Webserver

Publication: 2002-02-13
Summary

GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.

Risk level (CVSS 5)

Moderate

5.0

Access Vector

  • Network
  • Adjacent Network
  • Local

Access Complexity

  • Low
  • Medium
  • High

Authentication

  • None
  • Single
  • Multiple

Confident. Impact

  • Complete
  • Partial
  • None

Integrity Impact

  • Complete
  • Partial
  • None

Affected Products

  • Goahead Software Goahead Webserver 2.0
  • Goahead Software Goahead Webserver 2.1
  • Goahead Software Goahead Webserver 2.1.1
  • Goahead Software Goahead Webserver 2.1.2
  • Goahead Software Goahead Webserver 2.1.3
  • Goahead Software Goahead Webserver 2.1.4
  • Goahead Software Goahead Webserver 2.1.5
  • Goahead Software Goahead Webserver 2.1.6
  • Goahead Software Goahead Webserver 2.1.7