CVE-2002-2029

Publication date

2005-07-14 04:00:00

Family

mitre

State

PUBLISHED

Description

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.