CVE-2002-0061
published 2002-03-21CVE-2002-0061: Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe…
PriorityP353high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
56.70%
99.0th percentile
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 1.3.24 | 1.3.24 |
| apache | http_server | >= 2.0.0 < 2.0.34 | 2.0.34 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests to .bat or .cmd CGI scripts containing a pipe character '|' in the query string or URI arguments, which is the shell metacharacter used to inject arbitrary commands. ↗
- →Monitor HTTP GET requests targeting /cgi-bin/test-cgi.bat with a '|' character in the query string as the primary exploitation vector for this CVE on Apache Win32. ↗
- →Alert on any web-accessible .bat or .cmd file requests containing pipe '|' characters, as the vulnerability affects any batch file accessible via the web, not only the test-cgi.bat file. ↗
- →Note that exploitation typically results in command execution as SYSTEM; monitor for cmd.exe spawned as a child process of the Apache httpd process on Windows. ↗
- ·This vulnerability is Windows-platform specific and does not affect Apache on Linux/Unix systems. ↗
- ·Affected versions are Apache for Win32 before 1.3.24 and 2.0.x before 2.0.34-beta; the shell interpreter involved is typically cmd.exe. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hq5-3246-pmqx: Apache for Win32 before 1
ghsa_unreviewed·2022-04-30
CVE-2002-0061 [HIGH] CWE-78 GHSA-6hq5-3246-pmqx: Apache for Win32 before 1
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
Red Hat
CVE-2002-0061: Apache for Win32 before 1
vendor_redhat·CVSS 7.5
CVE-2002-0061 [HIGH] CVE-2002-0061: Apache for Win32 before 1
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
Statement: Not vulnerable. This flaw is specific to Apache HTTP server on Windows platforms.
No detection rules found.
No writeups or analysis indexed.
CWE
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
mitre_cwe
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
This weakness can lead to a vulnerability in environments in which the attacker does not have direct access to the operating system, such as in web applications. Alternately, if the weakness occurs in a privileged program, it could allow the attacker to specify commands that normally would not be accessible, or to call alternate commands with privileges that the attacker does not have. The problem is exacerbated if the compro
CWE
Path Equivalence: 'filename.' (Trailing Dot)
mitre_cwe·CVSS 5.0
CVE-2000-1114 [MEDIUM] CWE-42 Path Equivalence: 'filename.' (Trailing Dot)
CWE-42: Path Equivalence: 'filename.' (Trailing Dot)
The product accepts path input in the form of trailing dot ('filedir.') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Access Control. Impact: Bypass Protection Mechanism.
Observed Examples:
CVE-2000-1114: Source code disclosure using trailing dot
CVE-2002-1986: Source code disclosure using trailing dot
CVE-2004-2213: Source code disclosure using trailing dot
CVE-2005-3293: Source code disclosure using trailing dot
CVE-2004-0061: Bypass directory access restrictions using trailing dot in URL
CVE-2000-1133: Bypass directory access rest
http://marc.info/?l=bugtraq&m=101674082427358&w=2http://online.securityfocus.com/archive/1/263927http://www.apacheweek.com/issues/02-03-29#apache1324http://www.iss.net/security_center/static/8589.phphttp://www.securityfocus.com/bid/4335https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttp://marc.info/?l=bugtraq&m=101674082427358&w=2http://online.securityfocus.com/archive/1/263927http://www.apacheweek.com/issues/02-03-29#apache1324http://www.iss.net/security_center/static/8589.phphttp://www.securityfocus.com/bid/4335https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
2002-03-21
Published