Vulnerability record · CVE-2002-0661 · published 12 August 2002
CVE-2002-0661: Apache HTTP Server directory traversal via backslash sequences on Windows, OS2 and NetWare
Apache · Http Server
Apache 2.0 through 2.0.39 on Windows, OS2 and NetWare fails to properly handle backslash characters in path traversal sequences, allowing remote attackers to escape the document root. This lets an unauthenticated client read arbitrary files and, per the description, execute commands on the affected host.
Description
Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote file read and command execution with a very high EPSS score, though the affected platform scope is limited and no KEV listing exists.
What it is
Apache 2.0 through 2.0.39 on Windows, OS2 and NetWare fails to properly handle backslash characters in path traversal sequences, allowing remote attackers to escape the document root. This lets an unauthenticated client read arbitrary files and, per the description, execute commands on the affected host.
Impact
An attacker can read files outside the web root, exposing configuration, credential and application data, and can execute commands, which can lead to full host compromise.
Attack surface
Reachable over the network through normal HTTP requests to the web server; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Only Windows, OS2 and NetWare deployments are affected per the description.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high at 0.697 (99.3rd percentile), indicating substantial predicted exploitation activity; the vendor advisory is tagged Patch and Vendor Advisory.
What to do
- Upgrade Apache HTTP Server past 2.0.39 to a fixed release as directed by the vendor security bulletin
- If immediate upgrade is not possible, restrict or disable access to affected servers from untrusted networks
- Run the web server with least privilege and confine its file access so traversal cannot reach sensitive files
- Review server configuration and file permissions on Windows, OS2 and NetWare hosts to limit exposure of files outside the document root
Detection
- Inspect web server access logs for requests containing backslash characters or dot-dot sequences in the URL path
- Alert on HTTP requests that resolve to files outside the configured document root
- Monitor for unexpected file reads or command execution spawned by the web server process
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0661 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0661), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.