Back

CVE-2002-0934

Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.

Published: Oct 4, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
jon_hedley alienform2 1.5

GitHub Security Advisory GHSA-3pfq-9fq5-mfj5

Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.98%

Top 21% most likely to be exploited

Threat Score 26.2 / 100

Data Sources

NVD EPSS GitHub