7.5
CVSSv2

CVE-2002-2029

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote malicious users to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server 1.3.16

apache http server 1.3.17

apache http server 1.3.18

apache http server 1.3.19

apache http server 1.3.11

apache http server 1.3.13

apache http server 1.3.15

apache http server 1.3.20

apache http server 1.3.12

apache http server 1.3.14

Exploits

source: wwwsecurityfocuscom/bid/3786/info A vulnerability exists in the suggested default configuration for the Apache PHPEXE binary on Microsoft Windows platforms This issue has the potential to disclose the contents of arbitrary files to remote attackers As a result, it is possible for an attacker to append a filepath to the end of ...