CVE-2002-0654

Apache 2.0-2.0.39 - Info Disclosure

Title source: llm

Description

Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Auriemma Luigi · textremotewindows
https://www.exploit-db.com/exploits/21719

References (16)

Scores

EPSS 0.7504
EPSS Percentile 98.9%

Details

Status published
Products (9)
apache/http_server 2.0
apache/http_server 2.0.28 (3 CPE variants)
apache/http_server 2.0.32 (2 CPE variants)
apache/http_server 2.0.34 beta
apache/http_server 2.0.35
apache/http_server 2.0.36
apache/http_server 2.0.37
apache/http_server 2.0.38
apache/http_server 2.0.39
Published Sep 05, 2002
Tracked Since Feb 18, 2026