Lucene search

K
cveMitreCVE-2002-1080
HistoryOct 04, 2002 - 4:00 a.m.

CVE-2002-1080

2002-10-0404:00:00
mitre
web.nvd.nist.gov
28
cve-2002-1080
administration console
abyss web server
patch 2
remote attackers
gain privileges
modify server configuration

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.009

Percentile

82.4%

The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.

Affected configurations

Nvd
Node
aprelium_technologiesabyss_web_serverMatch1.0
OR
aprelium_technologiesabyss_web_serverMatch1.0.3
VendorProductVersionCPE
aprelium_technologiesabyss_web_server1.0cpe:2.3:a:aprelium_technologies:abyss_web_server:1.0:*:*:*:*:*:*:*
aprelium_technologiesabyss_web_server1.0.3cpe:2.3:a:aprelium_technologies:abyss_web_server:1.0.3:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.009

Percentile

82.4%

Related for CVE-2002-1080