CVE-2002-1052

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/10/2002
Last modified:
03/04/2025

Description

Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physical path of the server using two requests to the "aux" device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:w3c:jigsaw:2.2.1:*:*:*:*:*:*:*