VYPR
Unrated severityNVD Advisory· Published May 29, 2002· Updated Jun 16, 2026

CVE-2002-0249

CVE-2002-0249

Description

PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.

Affected products

2

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.