ID

VAR-200207-0043


CVE

CVE-2002-0680


TITLE

GoAhead Web Server Directory traversal vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200207-085

DESCRIPTION

Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228. GoAhead WebServer is prone to a directory traversal vulnerability

Trust: 1.35

sources: NVD: CVE-2002-0680 // BID: 89464 // VULHUB: VHN-5071 // VULMON: CVE-2002-0680

AFFECTED PRODUCTS

vendor:montavistamodel:hard hat linuxscope:eqversion:1.0

Trust: 1.6

vendor:goaheadmodel:webserverscope:eqversion:2.1.4

Trust: 1.0

vendor:goaheadmodel:webserverscope:eqversion:2.1.5

Trust: 1.0

vendor:goaheadmodel:webserverscope:eqversion:2.1.1

Trust: 1.0

vendor:goaheadmodel:webserverscope:eqversion:2.1.2

Trust: 1.0

vendor:orangemodel:web serverscope:eqversion:2.1

Trust: 1.0

vendor:goaheadmodel:webserverscope:eqversion:2.1.3

Trust: 1.0

vendor:orangemodel:software orange web serverscope:eqversion:2.1

Trust: 0.3

vendor:montavistamodel:software hard hat linuxscope:eqversion:1.0

Trust: 0.3

vendor:goaheadmodel:software goahead webserverscope:eqversion:2.1.5

Trust: 0.3

vendor:goaheadmodel:software goahead webserverscope:eqversion:2.1.4

Trust: 0.3

vendor:goaheadmodel:software goahead webserverscope:eqversion:2.1.3

Trust: 0.3

vendor:goaheadmodel:software goahead webserverscope:eqversion:2.1.2

Trust: 0.3

vendor:goaheadmodel:software goahead webserverscope:eqversion:2.1.1

Trust: 0.3

sources: BID: 89464 // CNNVD: CNNVD-200207-085 // NVD: CVE-2002-0680

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-0680
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200207-085
value: MEDIUM

Trust: 0.6

VULHUB: VHN-5071
value: MEDIUM

Trust: 0.1

VULMON: CVE-2002-0680
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-0680
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

VULHUB: VHN-5071
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5071 // VULMON: CVE-2002-0680 // CNNVD: CNNVD-200207-085 // NVD: CVE-2002-0680

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-0680

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200207-085

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-200207-085

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-5071 // VULMON: CVE-2002-0680

PATCH

title:alt3kx.github.iourl:https://github.com/alt3kx/alt3kx.github.io

Trust: 0.1

sources: VULMON: CVE-2002-0680

EXTERNAL IDS

db:NVDid:CVE-2002-0680

Trust: 2.1

db:OSVDBid:81099

Trust: 1.2

db:CNNVDid:CNNVD-200207-085

Trust: 0.7

db:VULNWATCHid:20020710 [VULNWATCH] WP-02-0001: GOAHEAD WEB SERVER DIRECTORY TRAVERSAL + CROSS SITE SCRIPTING

Trust: 0.6

db:BUGTRAQid:20020719 RE: [VULNWATCH] WP-02-0001: GOAHEAD WEB SERVER DIRECTORY TRAVERSAL + CROSS SITE SCRIPTING

Trust: 0.6

db:BUGTRAQid:20020710 WP-02-0001: GOAHEAD WEB SERVER DIRECTORY TRAVERSAL + CROSS SITE SCRIPTING

Trust: 0.6

db:BIDid:89464

Trust: 0.5

db:EXPLOIT-DBid:21607

Trust: 0.2

db:SEEBUGid:SSVID-75432

Trust: 0.1

db:VULHUBid:VHN-5071

Trust: 0.1

db:VULMONid:CVE-2002-0680

Trust: 0.1

sources: VULHUB: VHN-5071 // VULMON: CVE-2002-0680 // BID: 89464 // CNNVD: CNNVD-200207-085 // NVD: CVE-2002-0680

REFERENCES

url:http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0013.html

Trust: 2.1

url:http://freecode.com/projects/embedthis-goahead-webserver/releases/343539

Trust: 1.2

url:http://osvdb.org/81099

Trust: 1.2

url:http://marc.info/?l=bugtraq&m=102631742711795&w=2

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=102709382714597&w=2

Trust: 1.1

url:http://marc.theaimsgroup.com/?l=bugtraq&m=102631742711795&w=2

Trust: 0.9

url:http://marc.theaimsgroup.com/?l=bugtraq&m=102709382714597&w=2

Trust: 0.9

url:http://marc.info/?l=bugtraq&m=102631742711795&w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&m=102709382714597&w=2

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.securityfocus.com/bid/89464

Trust: 0.1

url:https://www.exploit-db.com/exploits/21607/

Trust: 0.1

sources: VULHUB: VHN-5071 // VULMON: CVE-2002-0680 // BID: 89464 // CNNVD: CNNVD-200207-085 // NVD: CVE-2002-0680

CREDITS

Unknown

Trust: 0.3

sources: BID: 89464

SOURCES

db:VULHUBid:VHN-5071
db:VULMONid:CVE-2002-0680
db:BIDid:89464
db:CNNVDid:CNNVD-200207-085
db:NVDid:CVE-2002-0680

LAST UPDATE DATE

2025-04-03T21:36:14.407000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5071date:2017-12-20T00:00:00
db:VULMONid:CVE-2002-0680date:2017-12-20T00:00:00
db:BIDid:89464date:2002-07-23T00:00:00
db:CNNVDid:CNNVD-200207-085date:2005-10-31T00:00:00
db:NVDid:CVE-2002-0680date:2025-04-03T01:03:51.193

SOURCES RELEASE DATE

db:VULHUBid:VHN-5071date:2002-07-23T00:00:00
db:VULMONid:CVE-2002-0680date:2002-07-23T00:00:00
db:BIDid:89464date:2002-07-23T00:00:00
db:CNNVDid:CNNVD-200207-085date:2002-07-23T00:00:00
db:NVDid:CVE-2002-0680date:2002-07-23T04:00:00