VulnerabilityModified
CVE-2002-0934
Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a ..
MEDIUM 6.4EPSS 1.98%
Does this matter?
Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- jon hedley/alienform2
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0068.html
- http://www.iss.net/security_center/static/9325.phpVendor Advisory
- http://www.securityfocus.com/bid/4983Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0068.html
- http://www.iss.net/security_center/static/9325.phpVendor Advisory
- http://www.securityfocus.com/bid/4983Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.