Vulnerabilities > CVE-2004-0173 - Directory Traversal vulnerability in Apache Cygwin

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
apache
exploit available

Summary

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

Exploit-Db

descriptionApache Cygwin 1.3.x/2.0.x Directory Traversal Vulnerability. CVE-2004-0173. Remote exploit for windows platform
idEDB-ID:23751
last seen2016-02-02
modified2004-02-24
published2004-02-24
reporterJeremy Bae
sourcehttps://www.exploit-db.com/download/23751/
titleApache Cygwin 1.3.x/2.0.x - Directory Traversal Vulnerability