First published: Fri Feb 07 2003(Updated: )
Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | =2.0.42 | |
Apache Http Server | =2.0.37 | |
Apache Http Server | =2.0.39 | |
Apache Http Server | =2.0.41 | |
Apache Http Server | =2.0.38 | |
Apache Http Server | =2.0.40 | |
Apache Http Server | =2.0.36 | |
Apache Http Server | =2.0.43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0017 is classified as a security vulnerability potentially allowing unauthorized file access.
To fix CVE-2003-0017, upgrade your Apache HTTP Server to version 2.0.44 or later.
CVE-2003-0017 affects Apache HTTP Server versions 2.0.36 to 2.0.43 on Windows platforms.
The consequences of CVE-2003-0017 include unauthorized access to sensitive files on the server.
CVE-2003-0017 is not a risk for current Apache users who have updated to version 2.0.44 or later.