CVE-2002-2029
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
- Apache Http Server
- = 1.3.11, 1.3.12, 1.3.13, 1.3.14, 1.3.15, 1.3.16, 1.3.17, 1.3.18, 1.3.19, 1.3.20
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 23.1% (98th percentile)
- NVD status
- Modified
- Published
- 2005-07-14
CVE-2002-2029 at NVD
1 known exploit for CVE-2002-2029
Proof-of-concept code and exploit modules indexed by Sploitus