Back

CVE-2004-0173

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

Published: Apr 15, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
apache http_server 0.8.11
apache http_server 0.8.14
apache http_server 1.0
apache http_server 1.0.2
apache http_server 1.0.3
apache http_server 1.0.5
apache http_server 1.1
apache http_server 1.1.1
apache http_server 1.2
apache http_server 1.2.5
apache http_server 1.3

GitHub Security Advisory GHSA-p97v-fpq8-vh9w

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier,...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 15.76%

Top 3% most likely to be exploited

Threat Score 24.7 / 100

Data Sources

NVD EPSS GitHub