5
CVSSv2

CVE-2002-0770

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Quake 2 (Q2) server 3.20 and 3.21 allows remote malicious users to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."

Vulnerable Product Search on Vulmon Subscribe to Product

id software quake 2i server 3.20

id software quake 2i server 3.21

Exploits

source: wwwsecurityfocuscom/bid/4744/info Quake II is a multiplayer game released by id Software The source code has been made publically available, and versions are available for Windows and Linux A vulnerability has been reported in some versions of the Quake II server While variable expansion is normally performed on the client sid ...