This is a known issue. Old builds of PHP were exposed to this problem. If you read PHP.net
PHP Security Update - Windows Version
[12-Mar-2002] Following up from the previous annoucement, PHP 4.1.2 has been released for windows. The delayed release is due to the fix of a further security issue only relating to the PHP for Windows version. More information on this change can be found here. All PHP - Windows users are encouraged to upgrade to the latest version.
PHP Security Update
[27-Feb-2002] Due to a security issue found in all versions of PHP (including 3.x and 4.x), a new version of PHP has been released. Details about the security issue are available here. All users of PHP are strongly encouraged to either upgrade to PHP 4.1.2, or install the patch (available for PHP 3.0.18, 4.0.6 and 4.1.0/4.1.1).