# CVE-2003-1569

## Summary

- **CVE ID:** CVE-2003-1569
- **Severity:** MEDIUM
- **CVSS Score:** 5 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
- **CWE:** N/A
- **Published:** Feb 6, 2009
- **Last Modified:** Mar 16, 2026

## Description

GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://data.goahead.com/Software/Webserver/2.1.8/release.htm#windows-95-98-me-aux-denial-of-service)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 62.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._