2025-04-03 02:06:18 +00:00

114 lines
3.1 KiB
JSON

{
"id": "CVE-2002-0266",
"sourceIdentifier": "cve@mitre.org",
"published": "2002-05-29T04:00:00.000",
"lastModified": "2025-04-03T01:03:51.193",
"vulnStatus": "Deferred",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname."
},
{
"lang": "es",
"value": "El script CGI Thunderstone Texis permite que atacantes remotos obtengan el path absoluto del web mediante una petici\u00f3n de fichero inexistente. Esto genera un mensaje de error que contiene el path completo."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:thunderstone_software:texis:3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "2E20DF06-1C75-444B-8312-9D6A010ED131"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=101301228031165&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=101346478229431&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/8103.php",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/4035",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=101301228031165&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=101346478229431&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/8103.php",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/4035",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}