PT-2002-1690 · Apache · Apache+1
Published
2002-08-09
·
Updated
2021-06-06
·
CVE-2002-0661
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache versions 2.0 through 2.0.39
Description
The issue allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing (backslash) characters. Certain URIs can bypass security and allow users to invoke or access any file depending on the system configuration. This affects Windows, OS2, Netware, and Cygwin platforms.
Recommendations
For Apache versions 2.0 through 2.0.39, consider restricting access to sensitive files and directories to minimize the risk of exploitation. As a temporary workaround, consider disabling the use of .. (dot dot) sequences containing (backslash) characters in URIs until a patch is available. Restrict access to sensitive URIs to prevent bypassing security measures.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Apache Http Server