Users login

Create an account »


Users login

Home » Hacking News » Apache 2 for Windows php.exe Path Disclosure Vulnerability

Apache 2 for Windows php.exe Path Disclosure Vulnerability

by Nikola Strahija on February 9th, 2002 A path disclosure vulnerability exists in the default configuration of some beta releases of Apache 2. If PHP is also installed with default values, it is possible to submit a malicious request to the web server such that the full path of the PHP interpreter is disclosed.

A url of the form http://host/file.php/123 will result in an error message, including in part the path of the file php.exe.

Exploit: This vulnerability can be exploited with a web browser.

Remote: Yes

Vulnerable: Apache Group Apache 2.0.28 Beta

Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.


Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »