Exploitation Summary
EIP tracks 1 public exploit for CVE-2002-0266. PoCs published by phinegeek.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in TEXIS. The vulnerability allows an attacker to view the full path to the web root by submitting an HTTP request for an invalid path.
Description
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by phinegeek · textremotemultiple
https://www.exploit-db.com/exploits/21276
This is a writeup describing an information disclosure vulnerability in TEXIS. The vulnerability allows an attacker to view the full path to the web root by submitting an HTTP request for an invalid path.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
TEXIS versions prior to 4.03.1049406926 20030403
No auth needed
Prerequisites:
Access to the TEXIS web server
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Vendor Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/8103.php
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/4035
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101301228031165&w=2
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101346478229431&w=2
Scores
EPSS
0.0845
EPSS Percentile
94.4%
Details
Status
published
Products (1)
thunderstone_software/texis
3.0
Published
May 29, 2002
Tracked Since
Feb 18, 2026