CVE-2002-0333 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 2.63% — more likely to be exploited than 85% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-06-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| xtell | xtell |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | xtell 2.6.1 - User Status Remote Information Disclosure | 2002-02-27 |
References
- http://marc.info/?l=bugtraq&m=101494896516467&w=2
- http://www.debian.org/security/2002/dsa-121
- http://www.iss.net/security_center/static/8313.php
- http://www.securityfocus.com/bid/4194
- http://marc.info/?l=bugtraq&m=101494896516467&w=2
- http://www.debian.org/security/2002/dsa-121
- http://www.iss.net/security_center/static/8313.php
- http://www.securityfocus.com/bid/4194
→ the Explorer · watch your stack · NVD