Apache 1.3.20 (Win32) - 'PHP.exe' Remote File Disclosure

EDB-ID:

21204




Platform:

Windows

Date:

2002-01-04


source: https://www.securityfocus.com/bid/3786/info

A vulnerability exists in the suggested default configuration for the Apache PHP.EXE binary on Microsoft Windows platforms. This issue has the potential to disclose the contents of arbitrary files to remote attackers.

As a result, it is possible for an attacker to append a filepath to the end of web request for php.exe. Files targetted in this manner will be served to the attacker.

It is also possible to run executables in the PHP directory via successful exploitation of this vulnerability.

http://[targethost]/php/php.exe?c:\[filepath]