CVE-2003-0097

critical

Description

Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).

References

http://www.slackware.com/changelog/current.php?cpu=i386

http://www.securityfocus.com/bid/6875

http://www.iss.net/security_center/static/11343.php

http://marc.info/?l=bugtraq&m=104567137502557&w=2

http://marc.info/?l=bugtraq&m=104567042700840&w=2

http://marc.info/?l=bugtraq&m=104550977011668&w=2

Details

Source: Mitre, NVD

Published: 2003-03-03

Updated: 2018-10-30

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Severity: Critical