Lucene search

K
cve[email protected]CVE-2002-0107
HistoryJun 25, 2002 - 4:00 a.m.

CVE-2002-0107

2002-06-2504:00:00
web.nvd.nist.gov
23
cve-2002-0107
cacheflow cacheos 4.0.13
web admin interface
remote attack
info leakage

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.1%

Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series of GET requests that do not end in with HTTP/1.0 or another version string, which causes the information to be leaked in the error message.

Affected configurations

NVD
Node
cacheflowcacheosMatch0.0
OR
cacheflowcacheosMatch3.1.02
OR
cacheflowcacheosMatch3.1.03
OR
cacheflowcacheosMatch3.1.04
OR
cacheflowcacheosMatch3.1.05
OR
cacheflowcacheosMatch3.1.06
OR
cacheflowcacheosMatch3.1.07
OR
cacheflowcacheosMatch3.1.08
OR
cacheflowcacheosMatch3.1.09
OR
cacheflowcacheosMatch3.1.10
OR
cacheflowcacheosMatch3.1.11
OR
cacheflowcacheosMatch3.1.12
OR
cacheflowcacheosMatch3.1.13
OR
cacheflowcacheosMatch3.1.14
OR
cacheflowcacheosMatch3.1.15
OR
cacheflowcacheosMatch3.1.16
OR
cacheflowcacheosMatch3.1.17
OR
cacheflowcacheosMatch3.1.18
OR
cacheflowcacheosMatch3.1.19
OR
cacheflowcacheosMatch3.1.20
OR
cacheflowcacheosMatch4.0.11
OR
cacheflowcacheosMatch4.0.12
OR
cacheflowcacheosMatch4.0.13

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.1%

Related for CVE-2002-0107