CVE-2002-0061
Apache HTTP Server < 1.3.24 - OS Command Injection
Title source: ruleDescription
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by SPAX · perlremotewindows
https://www.exploit-db.com/exploits/21350
References (9)
Scores
EPSS
0.8828
EPSS Percentile
99.5%
Details
CWE
CWE-78
Status
published
Products (1)
apache/http_server
< 1.3.24
Published
Mar 21, 2002
Tracked Since
Feb 18, 2026