First published: Mon Mar 03 2003(Updated: )
Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | =4.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0097 is considered to be a critical vulnerability due to the potential remote file access and execution of arbitrary code.
To fix CVE-2003-0097, update to a later version of PHP that has resolved this vulnerability.
CVE-2003-0097 specifically affects PHP version 4.3.0.
CVE-2003-0097 can be exploited by attackers to read arbitrary files and potentially execute PHP code on the server.
To determine if your system is vulnerable to CVE-2003-0097, check if you are running PHP version 4.3.0 without appropriate security measures.