5
CVSSv2

CVE-2001-0042

Published: 16/02/2001 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PHP 3.x (PHP3) on Apache 1.3.6 allows remote malicious users to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server 1.3

Exploits

source: wwwsecurityfocuscom/bid/2060/info Apache Web Server is subject to disclose files to unauthorized users when used in conjunction with the PHP3 script language By requesting a specially crafted URL by way of php, it is possible for a remote user to gain read access to a known file that resides on the target host Successful explo ...