Back

CVE-2002-0681

Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.

Published: Jul 23, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
goahead_software goahead_webserver 2.1.1
goahead_software goahead_webserver 2.1.2
goahead_software goahead_webserver 2.1.3
goahead_software goahead_webserver 2.1.4
goahead_software goahead_webserver 2.1.5

GitHub Security Advisory GHSA-8hmj-5wjj-pg73

Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 8.34%

Top 6% most likely to be exploited

Threat Score 32.5 / 100

Data Sources

NVD EPSS GitHub