First published: Fri Jan 12 2001(Updated: )
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | =4.0 | |
PHP | =4.0.1 | |
PHP | =4.0.3 | |
PHP | =4.0.4 | |
Mandrake Linux | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1385 has been rated as a moderate severity vulnerability.
To fix CVE-2001-1385, ensure that you configure the PHP engine correctly for each virtual host and avoid disabling it globally.
CVE-2001-1385 affects PHP versions 4.0.0 through 4.0.4 and certain versions of Mandrake Linux.
CVE-2001-1385 exploits the misconfiguration of the PHP engine in Apache, which can expose PHP source code due to improper settings.
Web administrators using PHP versions 4.0.0 to 4.0.4 with Apache configurations may be impacted by CVE-2001-1385.