CVE-2002-0934
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/10/2002
Last modified:
03/04/2025
Description
Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.
Impact
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:jon_hedley:alienform2:1.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0068.html
- http://www.iss.net/security_center/static/9325.php
- http://www.securityfocus.com/bid/4983
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0068.html
- http://www.iss.net/security_center/static/9325.php
- http://www.securityfocus.com/bid/4983