CVE-2002-0543 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 9.8% (pctl 95)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 9.79% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-07-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| aprelium technologies | abyss web server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Abyss Web Server 1.0 - File Disclosure | 2002-04-07 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0110.html
- http://www.aprelium.com/forum/viewtopic.php?t=24
- http://www.iss.net/security_center/static/8805.php
- http://www.securityfocus.com/bid/4466
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0110.html
- http://www.aprelium.com/forum/viewtopic.php?t=24
- http://www.iss.net/security_center/static/8805.php
- http://www.securityfocus.com/bid/4466
→ the Explorer · watch your stack · NVD