Vulnerability record · CVE-2002-0770 · published 12 August 2002
CVE-2002-0770: Id software quake 2i server vulnerability
IId Software · Quake 2i Server
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."
Description
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://online.securityfocus.com/archive/1/272548 | |
| http://www.iss.net/security_center/static/9095.php | Vendor Advisory |
| http://www.kb.cert.org/vuls/id/970915 | US Government Resource |
| http://www.osvdb.org/11187 | |
| http://www.quakesrc.org/forum/topicDisplay.php?topicID=160 | Vendor Advisory |
| http://www.securityfocus.com/bid/4744 | PatchVendor Advisory |
| http://online.securityfocus.com/archive/1/272548 | |
| http://www.iss.net/security_center/static/9095.php | Vendor Advisory |
| http://www.kb.cert.org/vuls/id/970915 | US Government Resource |
| http://www.osvdb.org/11187 | |
| http://www.quakesrc.org/forum/topicDisplay.php?topicID=160 | Vendor Advisory |
| http://www.securityfocus.com/bid/4744 | PatchVendor Advisory |
Track CVE-2002-0770 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2002-0770), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.