CVE-2002-0300
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and…
Does this matter?
Lower severity and a low EPSS score (7.33%). Track it; it rarely justifies an emergency change on its own.
Description
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.33% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- gnujsp/gnujsp
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101415804625292&w=2
- http://marc.info/?l=bugtraq&m=101422432123898&w=2
- http://www.debian.org/security/2002/dsa-114Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8240.php
- http://www.securityfocus.com/bid/4125
- http://marc.info/?l=bugtraq&m=101415804625292&w=2
- http://marc.info/?l=bugtraq&m=101422432123898&w=2
- http://www.debian.org/security/2002/dsa-114Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8240.php
- http://www.securityfocus.com/bid/4125
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.