5
CVSSv2

CVE-2002-1603

Published: 13/02/2002 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

GoAhead Web Server 2.1.7 and previous versions allows remote malicious users to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.

Vulnerable Product Search on Vulmon Subscribe to Product

goahead software goahead webserver 2.1.2

goahead software goahead webserver 2.1.3

goahead software goahead webserver 2.0

goahead software goahead webserver 2.1.6

goahead software goahead webserver 2.1.7

goahead software goahead webserver 2.1

goahead software goahead webserver 2.1.1

goahead software goahead webserver 2.1.4

goahead software goahead webserver 2.1.5

Exploits

source: wwwsecurityfocuscom/bid/9239/info A vulnerability in GoAhead webserver may result in the disclosure of the source code of ASP script files The vulnerability occurs because the application fails to sanitize HTTP requests An attacker can append certain characters to the end of an HTTP request for a specific ASP file As a result, ...