Apache HTTP Server Other Vulnerability - CVE-2002-2029
PHP when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/ allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.