CVE-2002-0298: Medium severity Nombas Scriptease Webserver vulnerability
ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0298?
CVE-2002-0298 is classified as a denial of service vulnerability.
How do I fix CVE-2002-0298?
To fix CVE-2002-0298, upgrade to a more secure version of the ScriptEase MiniWeb Server that is not vulnerable.
Who is affected by CVE-2002-0298?
CVE-2002-0298 affects users of ScriptEase MiniWeb Server version 0.95.
What types of attacks are demonstrated by CVE-2002-0298?
CVE-2002-0298 demonstrates denial of service attacks through specific HTTP GET requests that contain encoded dot-dot sequences.
What can happen if I do not mitigate CVE-2002-0298?
If CVE-2002-0298 is not mitigated, it may lead to the unavailability of the affected web server, disrupting services.