CVE-2002-0892
MEDIUM 5.0EPSS 7.6%
The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 7.56% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2003-04-02
- Updated
- 2024-08-08