VDB
CVE-2002-1603
CVE-2002-1603
PUBLISHED
CVSS 5 MEDIUM
GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.
EPSS 35.75% · 97.2th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
35.75%
97.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| goahead_software | goahead_webserver | 2.1.7, 2.0, 2.1 |
| n/a | n/a | n/a |
Timeline
- Feb 13, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 15, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- goahead-script-source-disclosure(10885) vdb
- VU#975041 third-party-advisory
- 7741 third-party-advisory
- VU#124059 third-party-advisory
- http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729 url
- http://www.procheckup.com/PDFs/ProCheckUp_Vulns_2002.pdf url
- http://data.goahead.com/Software/Webserver/2.1.8/release.htm#bug-with-urls-like-asp url
- http://www.kb.cert.org/vuls/id/RGII-7MWKZ3 url
- 9239 vdb
- http://aluigi.altervista.org/adv/goahead-adv3.txt url
- 1005820 vdb
- 13295 vdb
- http://www.procheckup.com/security_info/vuln_pr0213.html url
- https://nvd.nist.gov/vuln/detail/CVE-2002-1603 advisory