7.5

CVE-2002-2029

Exploit

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version1.3.11
ApacheHTTP Server Version1.3.12
ApacheHTTP Server Version1.3.13
ApacheHTTP Server Version1.3.14
ApacheHTTP Server Version1.3.15
ApacheHTTP Server Version1.3.16
ApacheHTTP Server Version1.3.17
ApacheHTTP Server Version1.3.18
ApacheHTTP Server Version1.3.19
ApacheHTTP Server Version1.3.20
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 60.62% 0.982
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P