CVE-2002-0680: Medium severity Goahead Software Goahead Webserver vulnerability
Published Jul 12, 2002
·Updated
Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.
Affected Software
7 affected components
Goahead Software Goahead Webserver=2.1.1
Goahead Software Goahead Webserver=2.1.5
Goahead Software Goahead Webserver=2.1.2
Goahead Software Goahead Webserver=2.1.4
Orange Software Orange Web Server=2.1
Goahead Software Goahead Webserver=2.1.3
Montavista Software Hard Hat Linux=1.0
Event History
Jul 12, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jul 23, 2002
Rejected
04:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2002-0680?
CVE-2002-0680 is classified as a moderate severity vulnerability due to its potential to expose sensitive files.
2
How do I fix CVE-2002-0680?
To fix CVE-2002-0680, upgrade the GoAhead Web Server to a version that does not contain this vulnerability.
3
What versions of GoAhead Web Server are affected by CVE-2002-0680?
CVE-2002-0680 affects GoAhead Web Server versions 2.1.1 through 2.1.5.
4
Can CVE-2002-0680 lead to unauthorized access?
Yes, CVE-2002-0680 can lead to unauthorized access to arbitrary files on the server.
5
Is CVE-2002-0680 a duplicate of another vulnerability?
Yes, CVE-2002-0680 is highly likely to be a duplicate of CVE-2001-0228.