Vulnerability Database

290,020

Total vulnerabilities in the database

CVE-2002-0654

Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.

  • Published: Sep 5, 2002
  • Updated: Apr 13, 2023
  • CVE: CVE-2002-0654
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:P/I:N/A:N

No CWE or OWASP classifications available.

Software From Fixed in
apache / http_server 2.0.28-beta 2.0.28-beta.x
apache / http_server 2.0.35 2.0.35.x
apache / http_server 2.0.37 2.0.37.x
apache / http_server 2.0.32-beta 2.0.32-beta.x
apache / http_server 2.0.34-beta 2.0.34-beta.x
apache / http_server 2.0.39 2.0.39.x
apache / http_server 2.0.32 2.0.32.x
apache / http_server 2.0.38 2.0.38.x
apache / http_server 2.0.36 2.0.36.x
apache / http_server 2.0.28 2.0.28.x
apache / http_server 2.0 2.0.x