5
CVSSv2

CVE-2002-0253

Published: 29/05/2002 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote malicious users to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.0.3

php php 4.0.4

php php 4.0.1

php php 4.0

php php 4.1.0

php php 4.1.2

php php 4.0.5

php php 4.0.6