exploit-db-mirror/exploits/windows/remote/21204.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

9 lines
No EOL
597 B
Text

source: https://www.securityfocus.com/bid/3786/info
A vulnerability exists in the suggested default configuration for the Apache PHP.EXE binary on Microsoft Windows platforms. This issue has the potential to disclose the contents of arbitrary files to remote attackers.
As a result, it is possible for an attacker to append a filepath to the end of web request for php.exe. Files targetted in this manner will be served to the attacker.
It is also possible to run executables in the PHP directory via successful exploitation of this vulnerability.
http://[targethost]/php/php.exe?c:\[filepath]