CVE-2002-0282 describes a path disclosure vulnerability in DCP-Portal versions 3.7 through 4.5. Remote attackers can exploit this by directly requesting add_user.php or by providing an invalid new_language parameter to contents.php, categories.php, or files.php, causing the server's physical path to be revealed in an error message. This vulnerability has a CVSS score of 5.0, indicating a medium severity, and allows for information disclosure (Confidentiality: Partial) with low attack complexity and no authentication required. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.7CPE matchmatch criteria | cpe:2.3:a:codeworx_technologies:dcp-portal:3.7:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:codeworx_technologies:dcp-portal:4.0:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:codeworx_technologies:dcp-portal:4.1:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:codeworx_technologies:dcp-portal:4.2:*:*:*:*:*:*:* | ||
4.5CPE matchmatch criteria | cpe:2.3:a:codeworx_technologies:dcp-portal:4.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.