Apache Web Server and PHP3 Allows Remote File Reading

Apache Web Servers running PHP3 allow remote files to be retrieved and read.

Steve Manzuik

December 5, 2000

1 Min Read
ITPro Today logo

Reported December 6, 2000 by CHINANSL

VERSIONS AFFECTED

DESCRIPTIONA security issue has been identified on Windows NT and Windows 2000 servers running Apache Web servers and PHP3. A malicious user can use this vulnerability to access the contents of various files.

DEMONSTRATION

For example, if a malicious user wants to access the httpd.conf file, runs the following command from his Web browser:

http://www.vulnerablecom/index.php3.%5c../..%5cconf/httpd.conf.

VENDOR RESPONSE

The vendor has been contacted, but no response has been received.  

CREDITDiscovered by CHINANSL

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like