Home » Hacking News » Apache 2 for Windows php.exe Path Disclosure Vulnerability
Apache 2 for Windows php.exe Path Disclosure Vulnerability
by Nikola Strahija on February 9th, 2002 A path disclosure vulnerability exists in the default configuration of some beta releases of Apache 2. If PHP is also installed with default values, it is possible to submit a malicious request to the web server such that the full path of the PHP interpreter is disclosed.
A url of the form http://host/file.php/123 will result in an error message, including in part the path of the file php.exe.
Exploit: This vulnerability can be exploited with a web browser.
Remote: Yes
Vulnerable: Apache Group Apache 2.0.28 Beta