Vulnerability Name: | CVE-2003-1307 | ||||||||
Assigned: | 2003-12-31 | ||||||||
Published: | 2003-12-31 | ||||||||
Updated: | 2018-10-19 | ||||||||
Summary: | ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. Note: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP." | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | ALLOWS_OTHER_ACCESS | ||||||||
References: | Source: MISC Type: Exploit http://bugs.php.net/38915 Source: MITRE Type: CNA CVE-2003-1307 Source: MISC Type: Exploit http://hackerdom.ru/~dimmo/phpexpl.c Source: BUGTRAQ Type: Exploit, Vendor Advisory 20031226 Hijacking Apache https by mod_php Source: BUGTRAQ Type: UNKNOWN 20061019 PHP "exec", "system", "popen" problem Source: BUGTRAQ Type: UNKNOWN 20061020 Re: PHP "exec", "system", "popen" (+small POC) Source: BID Type: Exploit 9302 | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |