Security Advisory

CVE-2002-2029

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2005-07-14 04:00:00
Last updated 2024-09-17 00:35:43
Assigner mitre
State PUBLISHED

Description

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.