5
CVE-2002-0654
- EPSS 75.04%
- Published 05.09.2002 04:00:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
Data is provided by the National Vulnerability Database (NVD)
Apache ≫ HTTP Server Version2.0
Apache ≫ HTTP Server Version2.0.28
Apache ≫ HTTP Server Version2.0.28 Updatebeta
Apache ≫ HTTP Server Version2.0.28 Updatebeta Editionwin32
Apache ≫ HTTP Server Version2.0.32
Apache ≫ HTTP Server Version2.0.32 Updatebeta Editionwin32
Apache ≫ HTTP Server Version2.0.34 Updatebeta Editionwin32
Apache ≫ HTTP Server Version2.0.35
Apache ≫ HTTP Server Version2.0.36
Apache ≫ HTTP Server Version2.0.37
Apache ≫ HTTP Server Version2.0.38
Apache ≫ HTTP Server Version2.0.39
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 75.04% | 0.988 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|