Back to search
CVE-2002-0253
Published: May 3, 2002
Modified: Aug 8, 2024
PUBLISHED
Description
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20020207 Advisory #3 - PHP & JSP
mailing-list
x_refsource_BUGTRAQ
php-slash-path-information(8122)
vdb-entry
x_refsource_XF
4063
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now