← back
CVE-2002-0654

CVE-2002-0654

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 59%
from disclosure to weapon0 days
Published on NVDAug 20
1st PoCAug 16
exploitation probability
59%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.