CVE-2002-2029

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

Scoring

CVSS base score
2.41
EPSS probability
48.12%
Published
2005-07-14
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs