Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Apr 16, 2026
CVE-2002-0770
CVE-2002-0770
Description
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."
Affected products
2cpe:2.3:a:id_software:quake_2i_server:3.20:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:id_software:quake_2i_server:3.20:*:*:*:*:*:*:*
- cpe:2.3:a:id_software:quake_2i_server:3.21:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/4744nvdPatchVendor Advisory
- www.iss.net/security_center/static/9095.phpnvdVendor Advisory
- www.quakesrc.org/forum/topicDisplay.phpnvdVendor Advisory
- www.kb.cert.org/vuls/id/970915nvdUS Government Resource
- online.securityfocus.com/archive/1/272548nvd
- www.osvdb.org/11187nvd
News mentions
0No linked articles in our index yet.