5

CVE-2001-1385

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version 4.0
Php ≫ Php Version 4.0.1
Php ≫ Php Version 4.0.3
Php ≫ Php Version 4.0.4
Mandrakesoft ≫ Mandrake Linux Version 7.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.61% 0.728
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000373
http://marc.info/?l=bugtraq&m=97957961212852
http://www.debian.org/security/2001/dsa-020
http://www.iss.net/security_center/static/5939.php
Patch
Vendor Advisory
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-013.php3
http://www.redhat.com/support/errata/RHSA-2000-136.html
Patch
http://www.securityfocus.com/bid/2205