Record summary

CVE-2004-0173 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBApache Cygwin 1.3.x/2.0.x - Directory TraversalExploitDB exploitby Jeremy BaeNot analyzed1 file
ExploitDB

PoC details

References

8