PHP Improper Input Validation Vulnerability - CVE-2008-3660
PHP 4.4.x before 4.4.9 and 5.x through 5.2.6 when used as a FastCGI module allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension as demonstrated using foo..php.