CVE-2002-1089 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 5.4% (pctl 92)
Patch early
A public exploit exists.
Description
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 5.45% — more likely to be exploited than 92% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-10-04 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| oracle | application server |
| oracle | reports |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Oracle Reports Server 6.0.8/9.0.2 - Information Disclosure | 2002-07-18 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0203.html
- http://www.iss.net/security_center/static/9628.php
- http://www.securityfocus.com/bid/5262
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0203.html
- http://www.iss.net/security_center/static/9628.php
- http://www.securityfocus.com/bid/5262
→ the Explorer · watch your stack · NVD