MEDIUM
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message
Published May 3, 2002
5.0
MEDIUMCVSS 2.0
EPSS 7.21%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.