CVE-2002-0524

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/08/2002
Last modified:
20/11/2024

Description

ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, which leak the pathname in an error message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:asp-nuke:asp-nuke:rc1:*:*:*:*:*:*:*
cpe:2.3:a:asp-nuke:asp-nuke:rc2:*:*:*:*:*:*:*