PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing %5c (encoded backslash) sequences.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Http_server |
Apache |
1.3 (including) |
1.3 (including) |
References