CVE-2003-0863: High severity PHP PHP vulnerability

Published Oct 15, 2003
·
Updated

The phpchecksafemodeincludedir function in fopenwrappers.c of PHP 4.3.x returns a success value (0) when the safemodeincludedir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.

Affected Software

3 affected components
PHP PHP=4.3.0
PHP PHP=4.3.2
PHP PHP=4.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In php.ini, set safe_mode_include_dir to a specific directory path (do not leave it unspecified) so php_check_safe_mode_include_dir does not return success due to an unspecified value.

    PHP safe_mode_include_dir = set to a specific directory path (non-empty)
  2. Operational

    Audit PHP applications and server configurations for file include/require usage (especially dynamic includes). Identify include sites that could be influenced by remote input and apply input validation, whitelisting, or other hardening to prevent remote file-include exploitation.

Event History

Oct 15, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Nov 17, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2003-0863?

CVE-2003-0863 is considered a high severity vulnerability due to its potential to allow remote file inclusion attacks.

2

How do I fix CVE-2003-0863?

To fix CVE-2003-0863, ensure that the 'safe_mode_include_dir' configuration option is explicitly set in PHP 4.3.x.

3

Which versions of PHP are affected by CVE-2003-0863?

CVE-2003-0863 affects PHP versions 4.3.0, 4.3.1, and 4.3.2.

4

What type of vulnerability is CVE-2003-0863?

CVE-2003-0863 is a file inclusion vulnerability that can be exploited due to improper handling of safe mode settings.

5

Can CVE-2003-0863 be exploited remotely?

Yes, CVE-2003-0863 can be exploited remotely, allowing attackers to include malicious files through PHP scripts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203