5
CVSSv2

CVE-2002-0107

Published: 25/03/2002 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Web administration interface in CacheFlow CacheOS 4.0.13 and previous versions allows remote malicious users to obtain sensitive information via a series of GET requests that do not end in with HTTP/1.0 or another version string, which causes the information to be leaked in the error message.

Vulnerable Product Search on Vulmon Subscribe to Product

cacheflow cacheos 3.1.02

cacheflow cacheos 3.1.03

cacheflow cacheos 3.1.11

cacheflow cacheos 3.1.12

cacheflow cacheos 3.1.19

cacheflow cacheos 3.1.20

cacheflow cacheos 0.0

cacheflow cacheos 3.1.08

cacheflow cacheos 3.1.09

cacheflow cacheos 3.1.10

cacheflow cacheos 3.1.17

cacheflow cacheos 3.1.18

cacheflow cacheos 3.1.04

cacheflow cacheos 3.1.05

cacheflow cacheos 3.1.13

cacheflow cacheos 3.1.14

cacheflow cacheos 4.0.11

cacheflow cacheos 4.0.12

cacheflow cacheos 3.1.06

cacheflow cacheos 3.1.07

cacheflow cacheos 3.1.15

cacheflow cacheos 3.1.16

cacheflow cacheos 4.0.13

Exploits

source: wwwsecurityfocuscom/bid/3841/info CacheOS is the firmware designed and distributed with CacheFlow web cache systems It is maintained and distributed by CacheFlow When a user connects to the system via the web administration interface on port 8081, and issues an HTTP standard-compliant request to the system, the system will prev ...