CNCVE编号:CNCVE-20020064 CVE编号: 安全级别:高 漏洞中文描述: PHP是使用广泛的脚本语言,主要用于WEB开发和CGI编程。 当使用Apache服务器时,一些默认配置的PHP版本存在路径泄漏的漏洞。如果PHP包含文件使用相对目录,可能引起包含引用失败。在PHP文件尾部添加斜杠'/',然后提交请求,将返回错误信息和包含文件的完整路径。'Require'引用一样存在这个问题。 漏洞英文描述: PHP is a widely deployed scripting language, designed for web based development and CGI programming. A path disclosure vulnerability exists in the default configuration of some releases of PHP when used with the Apache web server. If PHP include files are references with a relative directory, it is possible to cause the include statement to fail. Submitting a request for a php file appended with a trailing slash '/', will return an error message and the full path to the include file directory. 'Require' statements may also be susceptible to this issue. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0066.html 系统类型:其他 漏洞类型:配置错误