Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Windows php.exe Apache 2路径泄露漏洞
Vulnerability Description
Windows的PHP在安装Apache 2.0.28测试版将其用作standalone CGI模块,远程攻击者可以借助畸形参数如/123的请求获取php.exe的物理路径,该漏洞会在错误信息中泄露路径名称。
CVSS Information
N/A
Vulnerability Type
N/A