← Vulnerability feed

Vulnerability record · CVE-2002-2240 · published 31 December 2002

CVE-2002-2240: Myserver path traversal vulnerability

Myserver · Myserver

Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request.

5.0 CVSS 2.0 Medium EPSS 1.6% · top 24.9% CWE-22 · Path traversal
5.0CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-2240 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-2414Myserver vulnerabilityMyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors.EPSS 2.9%7.5CVE-2007-1588Myserver vulnerabilityserver.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privileges, which might allow remot…EPSS 1.3%5.0CVE-2008-5160Myserver vulnerabilityUnspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via multiple invalid requests with t…EPSS 3.5%5.0CVE-2005-1658Myserver vulnerabilityDirectory traversal vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to list the parent directory of the web root via a URL w…EPSS 1.5%5.0CVE-2004-2516Myserver vulnerabilityDirectory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number o…EPSS 8.4%5.0CVE-2004-2517Myserver vulnerabilitymyServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.EPSS 3.6%4.3CVE-2007-3364Myserver vulnerabilityCross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web scri…EPSS 4.2%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%

Source: NIST National Vulnerability Database (record CVE-2002-2240), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.