VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Apr 16, 2026

CVE-2002-0770

CVE-2002-0770

Description

Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."

Affected products

2
  • cpe:2.3:a:id_software:quake_2i_server:3.20:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:id_software:quake_2i_server:3.20:*:*:*:*:*:*:*
    • cpe:2.3:a:id_software:quake_2i_server:3.21:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.