CVE-2003-0097
Summary
| CVE | CVE-2003-0097 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-03-03 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect). |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'GLSA: mod_php (200302-09.1)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'GLSA: mod_php php' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| PHP CGI SAPI Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 'PHP Security Advisory: CGI vulnerability in PHP version 4.3.0' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| The Slackware Linux Project: Slackware ChangeLogs | af854a3a-2127-422b-91ae-364da2661108 | www.slackware.com | |
| ISS X-Force Database:php-cgi-sapi-access(11343): PHP could allow access to the CGI SAPI | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.