CVE-2002-0737

Sambar Server - Source Code Disclosure and Denial of Service via URL with Space and Null Character

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0737. PoCs published by pgrundl.

AI-analyzed exploit summary This exploit leverages a URL parsing vulnerability in Sambar Server to disclose source code of script files by appending a space and null character (%00) to the request. The server fails to properly parse the URL, resulting in an information leak.

Description

Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character.

Exploits (1)

exploitdb WORKING POC VERIFIED
by pgrundl · textremotecgi
https://www.exploit-db.com/exploits/21390

This exploit leverages a URL parsing vulnerability in Sambar Server to disclose source code of script files by appending a space and null character (%00) to the request. The server fails to properly parse the URL, resulting in an information leak.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Sambar Server (version not specified)
No auth needed
Prerequisites: Access to the target Sambar Server · Knowledge of script file paths
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_confirm
http://www.sambar.com/security.htm
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0026.html
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8876.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5123
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4533
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/268121

Scores

EPSS 0.0892
EPSS Percentile 94.7%

Details

Status published
Products (1)
sambar/sambar_server 5.1
Published Aug 12, 2002
Tracked Since Feb 18, 2026