CVE-2002-0107

CacheFlow CacheOS <4.0.13 - Info Disclosure

Title source: llm
STIX 2.1

Description

Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series of GET requests that do not end in with HTTP/1.0 or another version string, which causes the information to be leaked in the error message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Bjorn Djupvik · textremotemultiple
https://www.exploit-db.com/exploits/21212

References (4)

Core 4
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3841
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101052887431488&w=2
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/254167
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7835.php

Scores

EPSS 0.0647
EPSS Percentile 91.2%

Details

Status published
Products (23)
cacheflow/cacheos 0.0
cacheflow/cacheos 3.1.02
cacheflow/cacheos 3.1.03
cacheflow/cacheos 3.1.04
cacheflow/cacheos 3.1.05
cacheflow/cacheos 3.1.06
cacheflow/cacheos 3.1.07
cacheflow/cacheos 3.1.08
cacheflow/cacheos 3.1.09
cacheflow/cacheos 3.1.10
... and 13 more
Published Mar 25, 2002
Tracked Since Feb 18, 2026