6.4
CVSSv2

CVE-2002-0737

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

Sambar web server prior to 5.2 beta 1 allows remote malicious users to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character.

Vulnerable Product Search on Vulmon Subscribe to Product

sambar sambar server 5.1

Exploits

source: wwwsecurityfocuscom/bid/4533/info An issue has been discovered in Sambar Server, which could allow a user to reveal the source code of script files Submitting a request for a known script file along with a space and null character (%00), will successfully bypass the serverside URL parsing server/cgi-bin/environpl+%00 ...