CVE Database
/

CVE-2003-1307

Back to search

CVE-2003-1307

Published: Oct 23, 2006

Modified: Aug 8, 2024

PUBLISHED

Description

The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP.

VendorProductVersions

n/a

n/a

affected
n/a

References

20061019 PHP "exec", "system", "popen" problem
mailing-list
x_refsource_BUGTRAQ
20031226 Hijacking Apache https by mod_php
mailing-list
x_refsource_BUGTRAQ
9302
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now