CVE-2002-0215

agora.cgi 3.2r-4.0 - Information Disclosure via Debug Mode Error Message

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0215. PoCs published by superpetz.

AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in Agora.cgi when debug mode is enabled. The issue allows an attacker to retrieve the absolute path of the script directory by requesting a non-existent HTML file.

Description

Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.

Exploits (1)

exploitdb WRITEUP VERIFIED
by superpetz · textremotecgi
https://www.exploit-db.com/exploits/21249

This is a writeup describing an information disclosure vulnerability in Agora.cgi when debug mode is enabled. The issue allows an attacker to retrieve the absolute path of the script directory by requesting a non-existent HTML file.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Agora.cgi (version not specified)
No auth needed
Prerequisites: Debug mode enabled in Agora.cgi
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8011.php
Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/252761
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3976

Scores

EPSS 0.0747
EPSS Percentile 93.9%

Details

Status published
Products (33)
steve_kneizys/agora.cgi 3.2
steve_kneizys/agora.cgi 3.2a
steve_kneizys/agora.cgi 3.2b
steve_kneizys/agora.cgi 3.2c
steve_kneizys/agora.cgi 3.2d
steve_kneizys/agora.cgi 3.2e
steve_kneizys/agora.cgi 3.2f
steve_kneizys/agora.cgi 3.2g
steve_kneizys/agora.cgi 3.2h
steve_kneizys/agora.cgi 3.2i
... and 23 more
Published May 16, 2002
Tracked Since Feb 18, 2026