CVE-2002-0654
Apache 2.0-2.0.39 - Info Disclosure
Title source: llmDescription
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Auriemma Luigi · textremotewindows
https://www.exploit-db.com/exploits/21719
References (16)
Scores
EPSS
0.7504
EPSS Percentile
98.9%
Details
Status
published
Products (9)
apache/http_server
2.0
apache/http_server
2.0.28 (3 CPE variants)
apache/http_server
2.0.32 (2 CPE variants)
apache/http_server
2.0.34 beta
apache/http_server
2.0.35
apache/http_server
2.0.36
apache/http_server
2.0.37
apache/http_server
2.0.38
apache/http_server
2.0.39
Published
Sep 05, 2002
Tracked Since
Feb 18, 2026