Vulnerability Name: | CVE-2002-1951 (CCN-9884) | ||||||||
Assigned: | 2002-08-14 | ||||||||
Published: | 2002-08-14 | ||||||||
Updated: | 2017-12-20 | ||||||||
Summary: | Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2002-1951 Source: CONFIRM Type: UNKNOWN http://freecode.com/projects/embedthis-goahead-webserver/releases/343539 Source: OSVDB Type: UNKNOWN 81099 Source: CCN Type: Full-Disclosure Mailing List, Thu, 27 Dec 2007 20:27:31 -0600 Ho Ho H0-Day - ZyXEL P-330W multiple XSS and XSRF vulnerabilities Source: CCN Type: GoAhead Software Web site GoAhead WebServer Source: XF Type: Patch goahead-long-url-bo(9884) Source: CCN Type: OSVDB ID: 59786 GoAhead WebServer HTTP GET Request Subdirectory Handling Remote Overflow Source: CCN Type: SecuriTeam Mailing List, SecurityNews 14 Aug 2002 GoAhead Buffer Overflows (Multiple Slashes, Exploit) Source: MISC Type: Exploit, Patch http://www.securiteam.com/securitynews/5MP0C1580W.html Source: BID Type: Exploit, Patch 5464 Source: CCN Type: BID-5464 GoAhead WebServer Remote Arbitrary Command Execution Vulnerability Source: XF Type: UNKNOWN goahead-long-url-bo(9884) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |