CVE-2002-1603: Medium severity Goahead Software Goahead Webserver vulnerability
Published Feb 13, 2002
·Updated
GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.
Affected Software
9 affected components
Goahead Software Goahead Webserver=2.1.1
Goahead Software Goahead Webserver=2.0
Goahead Software Goahead Webserver=2.1.5
Goahead Software Goahead Webserver=2.1.2
Goahead Software Goahead Webserver=2.1.4
Goahead Software Goahead Webserver=2.1.7
Goahead Software Goahead Webserver=2.1
Goahead Software Goahead Webserver=2.1.3
Goahead Software Goahead Webserver=2.1.6
Event History
Feb 13, 2002
CVE Published
05:00 AM
Mar 25, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1603?
CVE-2002-1603 has been classified with a high severity due to potential information disclosure risks.
2
How do I fix CVE-2002-1603?
To mitigate CVE-2002-1603, upgrade to a version of GoAhead Web Server that is later than 2.1.7.
3
What impact does CVE-2002-1603 have on affected systems?
CVE-2002-1603 allows remote attackers to view the source code of ASP files, leading to potential data exposure.
4
Which versions of GoAhead Web Server are affected by CVE-2002-1603?
CVE-2002-1603 affects GoAhead Web Server versions 2.1.7 and earlier.
5
Can CVE-2002-1603 be exploited remotely?
Yes, CVE-2002-1603 can be exploited remotely by sending specially crafted requests to the web server.