CVE-2004-1063: Critical severity PHP PHP vulnerability
PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safemodeexecdir restrictions and execute commands outside of the intended safemodeexecdir via shell metacharacters in the current directory name. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1063?
CVE-2004-1063 is considered to have a moderate severity due to the potential for local users to execute commands outside designated directories.
How do I fix CVE-2004-1063?
To fix CVE-2004-1063, users should upgrade to a patched version of PHP that is beyond 4.3.9 or 5.0.2.
Who is affected by CVE-2004-1063?
CVE-2004-1063 affects PHP versions 4.x up to 4.3.9 and 5.x up to 5.0.2 when running in safe mode.
What systems are vulnerable to CVE-2004-1063?
Vulnerable systems include multithreaded Unix web servers running specific versions of PHP under safe mode.
What mitigations exist for CVE-2004-1063?
Mitigations for CVE-2004-1063 include disabling safe mode or applying the latest security patches for affected PHP versions.