|
|
| |
| A security vulnerability has been found in Windows NT/2000 systems that have Apache and PHP installed. The vulnerability allows remote attackers to access files outside the document root directory scope. |
| |
Credit:
The information has been provided by china nsl.
|
| |
Vulnerable systems:
Apache 1.3.6 and PHP3 under Windows 2000
By sending the following URL request:
http://www.example.com/index.php3.%5c../..%5cconf/httpd.conf
It is possible to cause the Apache server to send back the content of /etc/httpd.conf.
|
|
|
|
|