Back

CVE-2002-2403

Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.

Published: Dec 31, 2002 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (1)

Vendor Product Version
key_focus kf_web_server 1.0.8

GitHub Security Advisory GHSA-g98v-rw9m-98w8

Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 2.67%

Top 16% most likely to be exploited

Threat Score 20.8 / 100

Data Sources

NVD EPSS GitHub