CVE
- Id
- 5160
- CVE No.
- CVE-2002-0770
- Status
- Candidate
- Description
- Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."
- Phase
- Modified (20051128)
- Votes
- NOOP(5) Armstrong, Cole, Cox, Foat, Wall
- Comments