← Vulnerability feed

Vulnerability record · CVE-2002-0407 · published 26 July 2002

CVE-2002-0407: Lotus domino vulnerability

Lotus · Domino

htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes htcgibin.exe to leak the pathname in an error message.

5.0 CVSS 2.0 Medium EPSS 2.8% · top 14.2%
5.0CVSS 2.0 base score
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes htcgibin.exe to leak the pathname in an error message.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0407 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2001-0846Lotus domino vulnerabilityLotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (…EPSS 41%10.0CVE-2000-1046Lotus domino vulnerabilityMultiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly ex…EPSS 6.1%7.5CVE-2002-0245Lotus domino vulnerabilityLotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexist…EPSS 2.5%5.0CVE-2002-2191Lotus domino vulnerabilityLotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive infor…EPSS 2.9%5.0CVE-2002-0408Lotus domino vulnerabilityhtcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version n…EPSS 1.7%5.0CVE-2001-0954Lotus domino vulnerabilityLotus Domino 5.0.5 and 5.0.8, and possibly other versions, allows remote attackers to cause a denial of service (block access to databases that have …EPSS 1.6%5.0CVE-2001-0939Lotus domino vulnerabilityLotus Domino 5.08 and earlier allows remote attackers to cause a denial of service (crash) via a SunRPC NULL command to port 443.EPSS 1.6%5.0CVE-2001-1018Lotus domino vulnerabilityLotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that co…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2002-0407), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.