CVE-2002-0874

Interchange <4.8.6 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0874. PoCs published by anonymous.

AI-analyzed exploit summary The writeup describes a directory traversal vulnerability in Interchange 4.8.5 and earlier, allowing attackers to read arbitrary files via '../' sequences in HTTP requests when the service runs in INET mode.

Description

Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.

Exploits (1)

exploitdb WRITEUP VERIFIED
by anonymous · textremotelinux
https://www.exploit-db.com/exploits/21706

The writeup describes a directory traversal vulnerability in Interchange 4.8.5 and earlier, allowing attackers to read arbitrary files via '../' sequences in HTTP requests when the service runs in INET mode.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Interchange 4.8.5 and earlier
No auth needed
Prerequisites: Interchange service running in INET mode · Access to the vulnerable endpoint
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2002/dsa-150

Scores

EPSS 0.0584
EPSS Percentile 92.4%

Details

Status published
Products (5)
redhat/interchange 4.8.1
redhat/interchange 4.8.2
redhat/interchange 4.8.3
redhat/interchange 4.8.4
redhat/interchange 4.8.5
Published Sep 05, 2002
Tracked Since Feb 18, 2026