[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2002-2029Date: (C)2002-12-31   (M)2023-12-22


PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-3786
apache-php-view-files(7815)
http://www.securiteam.com/windowsntfocus/5ZP030U60U.html

CPE    10
cpe:/a:apache:http_server:1.3.18
cpe:/a:apache:http_server:1.3.17
cpe:/a:apache:http_server:1.3.19
cpe:/a:apache:http_server:1.3.14
...

© SecPod Technologies