CVE-2002-0893
NewAtlanta ServletExec ISAPI 4.1 - Directory Traversal via URL-Encoded Dot-Dot Sequences
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0893. PoCs published by Matt Moore.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in ServletExec/ISAPI to disclose arbitrary files within the webroot directory via URL-encoded sequences. The attack is limited to files within the webroot and does not allow breaking out of it.
Description
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences.
Exploits (1)
This exploit leverages a directory traversal vulnerability in ServletExec/ISAPI to disclose arbitrary files within the webroot directory via URL-encoded sequences. The attack is limited to files within the webroot and does not allow breaking out of it.