VulnerabilityModified
CVE-2002-0240
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
MEDIUM 5.0EPSS 7.42%
Does this matter?
Lower severity and a low EPSS score (7.42%). Track it; it rarely justifies an emergency change on its own.
Description
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.42% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101311746611160&w=2
- http://www.iss.net/security_center/static/8119.php
- http://www.securityfocus.com/bid/4057Vendor Advisory
- http://marc.info/?l=bugtraq&m=101311746611160&w=2
- http://www.iss.net/security_center/static/8119.php
- http://www.securityfocus.com/bid/4057Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.