LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2002-0934

CVE-2002-0934

CVSS 6.4 · MEDIUM

Summary

Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.

CVSS 2.0 breakdown

Base score6.4 (MEDIUM)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Attack vectorNETWORK
Attack complexityLOW
ConfidentialityPARTIAL
IntegrityPARTIAL
AvailabilityNONE

Affected products

Jon_hedley alienform2
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top