CVE
- Id
- 237
- CVE No.
- CVE-1999-0238
- Status
- Candidate
- Description
- php.cgi allows attackers to read any file on the system.
- Phase
- Proposed (19990623)
- Votes
- ACCEPT(5) Baker, Collins, Frech, Northcutt, Prosser | NOOP(1) Christey
- Comments
- Prosser> additional source | AUSCERT External Security Bulletin ESB-97.047 | http://www.auscert.org.au | Christey> ADDREF BUGTRAQ:19970416 Update on PHP/FI hole | URL:http://www.dataguard.no/bugtraq/1997_2/0069.html | The attacker specifies the filename as an argument to the | program. | Add "PHP/FI" to description to facilitate search. | AUSCERT URL is ftp://ftp.auscert.org.au/pub/auscert/ESB/ESB-97.047 | Christey> Consider adding BID:2250