SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-1603

GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.

MEDIUM 5.0EPSS 13.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 13.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
13.67% probability · 96th percentile
CISA KEV
Not listed
Affected
goahead software/goahead webserver
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.