{"api_version":"1","generated_at":"2026-07-23T02:17:38+00:00","cve":"CVE-2003-0097","urls":{"html":"https://cve.report/CVE-2003-0097","api":"https://cve.report/api/cve/CVE-2003-0097.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0097","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0097"},"summary":{"title":"CVE-2003-0097","description":"Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).","state":"PUBLISHED","assigner":"mitre","published_at":"2003-03-03 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=104567137502557&w=2","name":"http://marc.info/?l=bugtraq&m=104567137502557&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'GLSA:  mod_php (200302-09.1)' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://marc.info/?l=bugtraq&m=104567042700840&w=2","name":"http://marc.info/?l=bugtraq&m=104567042700840&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'GLSA:  mod_php php' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6875","name":"http://www.securityfocus.com/bid/6875","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP CGI SAPI Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=104550977011668&w=2","name":"http://marc.info/?l=bugtraq&m=104550977011668&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'PHP Security Advisory: CGI vulnerability in PHP version 4.3.0' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.slackware.com/changelog/current.php?cpu=i386","name":"http://www.slackware.com/changelog/current.php?cpu=i386","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"The Slackware Linux Project: Slackware ChangeLogs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/11343.php","name":"http://www.iss.net/security_center/static/11343.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database:php-cgi-sapi-access(11343): PHP could allow access to the CGI SAPI","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0097","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0097","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"97","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"4.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:43:36.008Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"GLSA-200302-09","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=104567042700840&w=2"},{"name":"GLSA-200302-09.1","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=104567137502557&w=2"},{"name":"php-cgi-sapi-access(11343)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/11343.php"},{"name":"20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=104550977011668&w=2"},{"name":"6875","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6875"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.slackware.com/changelog/current.php?cpu=i386"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-02-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2004-08-11T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"GLSA-200302-09","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://marc.info/?l=bugtraq&m=104567042700840&w=2"},{"name":"GLSA-200302-09.1","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://marc.info/?l=bugtraq&m=104567137502557&w=2"},{"name":"php-cgi-sapi-access(11343)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/11343.php"},{"name":"20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=104550977011668&w=2"},{"name":"6875","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6875"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.slackware.com/changelog/current.php?cpu=i386"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0097","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-200302-09","refsource":"GENTOO","url":"http://marc.info/?l=bugtraq&m=104567042700840&w=2"},{"name":"GLSA-200302-09.1","refsource":"GENTOO","url":"http://marc.info/?l=bugtraq&m=104567137502557&w=2"},{"name":"php-cgi-sapi-access(11343)","refsource":"XF","url":"http://www.iss.net/security_center/static/11343.php"},{"name":"20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=104550977011668&w=2"},{"name":"6875","refsource":"BID","url":"http://www.securityfocus.com/bid/6875"},{"name":"http://www.slackware.com/changelog/current.php?cpu=i386","refsource":"CONFIRM","url":"http://www.slackware.com/changelog/current.php?cpu=i386"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0097","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2003-02-18T00:00:00.000Z","dateUpdated":"2024-08-08T01:43:36.008Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-03-03 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*","matchCriteriaId":"63190D9B-7958-4B93-87C6-E7D5A572F6DC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"97","Ordinal":"1","Title":"CVE-2003-0097","CVE":"CVE-2003-0097","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"97","Ordinal":"1","NoteData":"Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).","Type":"Description","Title":"CVE-2003-0097"},{"CveYear":"2003","CveId":"97","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"97","Ordinal":"3","NoteData":"2004-08-10","Type":"Other","Title":"Modified"}]}}}