PT-2002-1690 · Apache · Apache+1

Published

2002-08-09

·

Updated

2021-06-06

·

CVE-2002-0661

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache versions 2.0 through 2.0.39
Description The issue allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing (backslash) characters. Certain URIs can bypass security and allow users to invoke or access any file depending on the system configuration. This affects Windows, OS2, Netware, and Cygwin platforms.
Recommendations For Apache versions 2.0 through 2.0.39, consider restricting access to sensitive files and directories to minimize the risk of exploitation. As a temporary workaround, consider disabling the use of .. (dot dot) sequences containing (backslash) characters in URIs until a patch is available. Restrict access to sensitive URIs to prevent bypassing security measures.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0661

Affected Products

Apache
Apache Http Server