CVE
- Id
- 4632
- CVE No.
- CVE-2002-0240
- Status
- Candidate
- Description
- PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
- Phase
- Proposed (20020502)
- Votes
- ACCEPT(2) Baker, Frech | MODIFY(1) Cox | NOOP(4) Armstrong, Cole, Foat, Wall
- Comments
- CHANGE> [Cox changed vote from REVIEWING to MODIFY] | Cox> Change to "....installed with Apache 2.0 for Windows"