← All CVEs

CVE-2002-1603

medium · 5

GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.

5
CVSS
13.7%
EPSS (exploit prob.)
96th
EPSS percentile
2002-02-13
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

VendorProductAffected versions
goahead_softwaregoahead_webserver2.0
goahead_softwaregoahead_webserver2.1
goahead_softwaregoahead_webserver2.1.1
goahead_softwaregoahead_webserver2.1.2
goahead_softwaregoahead_webserver2.1.3
goahead_softwaregoahead_webserver2.1.4
goahead_softwaregoahead_webserver2.1.5
goahead_softwaregoahead_webserver2.1.6
goahead_softwaregoahead_webserver2.1.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1603