CVE-2002-0786 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.2% (pctl 88)
Patch early
A public exploit exists.
Description
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.19% — more likely to be exploited than 88% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-08-12 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| critical path | injoin directory server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Critical Path InJoin Directory Server 4.0 - File Disclosure | 2002-05-10 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0068.html
- http://www.iss.net/security_center/static/9054.php
- http://www.securityfocus.com/bid/4718
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0068.html
- http://www.iss.net/security_center/static/9054.php
- http://www.securityfocus.com/bid/4718
→ the Explorer · watch your stack · NVD