CVE-2002-0061
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 50.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 50.37% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- apache/http server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101674082427358&w=2Mailing List, Third Party Advisory
- http://online.securityfocus.com/archive/1/263927Broken Link, Third Party Advisory, VDB Entry
- http://www.apacheweek.com/issues/02-03-29#apache1324Release Notes
- http://www.iss.net/security_center/static/8589.phpBroken Link
- http://www.securityfocus.com/bid/4335Broken Link, Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3EIssue Tracking, Mailing List, Vendor Advisory
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3EIssue Tracking, Mailing List, Vendor Advisory
- https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3EIssue Tracking, Mailing List, Vendor Advisory
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3EIssue Tracking, Mailing List, Vendor Advisory
- http://marc.info/?l=bugtraq&m=101674082427358&w=2Mailing List, Third Party Advisory
- http://online.securityfocus.com/archive/1/263927Broken Link, Third Party Advisory, VDB Entry
- http://www.apacheweek.com/issues/02-03-29#apache1324Release Notes
- http://www.iss.net/security_center/static/8589.phpBroken Link
- http://www.securityfocus.com/bid/4335Broken Link, Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3EIssue Tracking, Mailing List, Vendor Advisory
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3EIssue Tracking, Mailing List, Vendor Advisory
- https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3EIssue Tracking, Mailing List, Vendor Advisory
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3EIssue Tracking, Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.