CVE
- Id
- 4641
- CVE No.
- CVE-2002-0249
- Status
- Candidate
- Description
- PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
- Phase
- Proposed (20020502)
- Votes
- ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall
- Comments