CVE-2002-0654
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
- Affected products
- Apache, Apache Http Server
- Apache Http Server
- = 2.0, 2.0.28, 2.0.32, 2.0.34, 2.0.35, 2.0.36, 2.0.37, 2.0.38, 2.0.39
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 58.7% (99th percentile)
- NVD status
- Modified
- Published
- 2002-08-20
CVE-2002-0654 at NVD
1 known exploit for CVE-2002-0654
Proof-of-concept code and exploit modules indexed by Sploitus