CVE Vulnerabilities

CVE-2004-0173

Published: Apr 15, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing ..%5C (dot dot encoded backslash) sequences.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache0.8.11 (including)0.8.11 (including)
Http_serverApache0.8.14 (including)0.8.14 (including)
Http_serverApache1.0 (including)1.0 (including)
Http_serverApache1.0.2 (including)1.0.2 (including)
Http_serverApache1.0.3 (including)1.0.3 (including)
Http_serverApache1.0.5 (including)1.0.5 (including)
Http_serverApache1.1 (including)1.1 (including)
Http_serverApache1.1.1 (including)1.1.1 (including)
Http_serverApache1.2 (including)1.2 (including)
Http_serverApache1.2.5 (including)1.2.5 (including)
Http_serverApache1.3 (including)1.3 (including)

References