CVE-2002-0202 describes insecure file and directory permissions in PaintBBS 1.2, allowing local users to read the encrypted server password from oekakibbs.conf or modify server configurations in the /oekaki/ folder. With a CVSS score of 3.6 (low severity), this vulnerability requires local access and has low attack complexity, potentially leading to information disclosure and configuration alteration. There is no evidence of active exploitation, and no public exploit code is available, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2CPE matchmatch criteria | cpe:2.3:a:paintbbs:paintbbs:1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.