Vulnerabilities > CVE-2002-1603 - Unspecified vulnerability in Goahead Software Goahead Webserver

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
goahead-software
exploit available

Summary

GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.

Exploit-Db

descriptionGoAhead Webserver 2.1.x ASP Script File Source Code Disclosure Vulnerability. CVE-2002-1603. Remote exploit for windows platform
idEDB-ID:23446
last seen2016-02-02
modified2002-12-17
published2002-12-17
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/23446/
titleGoAhead Webserver 2.1.x ASP Script File Source Code Disclosure Vulnerability