Total vulnerabilities in the database
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
Software | From | Fixed in |
---|---|---|
apache / http_server | 1.3.16 | 1.3.16.x |
apache / http_server | 1.3.19 | 1.3.19.x |
apache / http_server | 1.3.20 | 1.3.20.x |
apache / http_server | 1.3.13 | 1.3.13.x |
apache / http_server | 1.3.18 | 1.3.18.x |
apache / http_server | 1.3.12 | 1.3.12.x |
apache / http_server | 1.3.17 | 1.3.17.x |
apache / http_server | 1.3.15 | 1.3.15.x |
apache / http_server | 1.3.14 | 1.3.14.x |
apache / http_server | 1.3.11 | 1.3.11.x |