VulnerabilityModified
CVE-2002-0786
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter.
MEDIUM 5.0EPSS 3.19%
Does this matter?
Lower severity and a low EPSS score (3.19%). Track it; it rarely justifies an emergency change on its own.
Description
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.19% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- critical path/injoin directory server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0068.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/9054.phpPatch, Vendor Advisory
- http://www.securityfocus.com/bid/4718Exploit, Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0068.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/9054.phpPatch, Vendor Advisory
- http://www.securityfocus.com/bid/4718Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.