CVE-2002-2427

The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603.

Scoring

Severity
MEDIUM
CVSS base score
5
CVSS vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS probability
0.30%
Published
2009-02-06
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs