SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0240

PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.

MEDIUM 5.0EPSS 7.42%

Does this matter?

Lower severity and a low EPSS score (7.42%). Track it; it rarely justifies an emergency change on its own.

Description

PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
7.42% probability · 94th percentile
CISA KEV
Not listed
Affected
apache/http server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.