4.3
CVE-2003-1307
- EPSS 1.62%
- Veröffentlicht 31.12.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:03:54
- Erkennungen
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ HTTP Server Version 2.0
Apache ≫ HTTP Server Version 2.0.9
Apache ≫ HTTP Server Version 2.0.28
Apache ≫ HTTP Server Version 2.0.28 Update beta
Apache ≫ HTTP Server Version 2.0.28 Update beta Edition win32
Apache ≫ HTTP Server Version 2.0.32
Apache ≫ HTTP Server Version 2.0.32 Update beta Edition win32
Apache ≫ HTTP Server Version 2.0.34 Update beta Edition win32
Apache ≫ HTTP Server Version 2.0.35
Apache ≫ HTTP Server Version 2.0.36
Apache ≫ HTTP Server Version 2.0.37
Apache ≫ HTTP Server Version 2.0.38
Apache ≫ HTTP Server Version 2.0.39
Apache ≫ HTTP Server Version 2.0.40
Apache ≫ HTTP Server Version 2.0.41
Apache ≫ HTTP Server Version 2.0.42
Apache ≫ HTTP Server Version 2.0.43
Apache ≫ HTTP Server Version 2.0.44
Apache ≫ HTTP Server Version 2.0.45
Apache ≫ HTTP Server Version 2.0.46
Apache ≫ HTTP Server Version 2.0.46 Edition win32
Apache ≫ HTTP Server Version 2.0.47
Apache ≫ HTTP Server Version 2.0.48
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.62% | 0.734 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 3.1 | 6.4 |
AV:L/AC:L/Au:S/C:P/I:P/A:P
|
http://bugs.php.net/38915
http://hackerdom.ru/~dimmo/phpexpl.c
http://www.securityfocus.com/archive/1/348368
http://www.securityfocus.com/archive/1/449234/100/0/threaded
http://www.securityfocus.com/archive/1/449298/100/0/threaded
http://www.securityfocus.com/bid/9302