peter bassill · operator
$ cve CVE-2002-0543 JSON

CVE-2002-0543 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 9.8% (pctl 95)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS9.79% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2002-07-03
Last modified2026-06-16

Affected (1)

VendorProduct
aprelium technologiesabyss web server

Public exploits

SourceTitleDate
exploit-dbAbyss Web Server 1.0 - File Disclosure2002-04-07

References

→ the Explorer  ·  watch your stack  ·  NVD