Apache Web Server and PHP3 Allows Remote File Reading
Apache Web Servers running PHP3 allow remote files to be retrieved and read.
Steve Manzuik
December 5, 2000
1 Min Read
Reported December 6, 2000 by CHINANSL VERSIONS AFFECTED DESCRIPTIONA security issue has been identified on Windows NT and Windows 2000 servers running Apache Web servers and PHP3. A malicious user can use this vulnerability to access the contents of various files. DEMONSTRATION For example, if a malicious user wants to access the httpd.conf file, runs the following command from his Web browser: http://www.vulnerablecom/index.php3.%5c../..%5cconf/httpd.conf. VENDOR RESPONSE The vendor has been contacted, but no response has been received. CREDITDiscovered by CHINANSL |
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like