Input validation error in PHP - CVE-2003-0097

 

Input validation error in PHP - CVE-2003-0097

Published: October 30, 2018 / Updated: June 8, 2025


Vulnerability identifier: #VU110532
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2003-0097
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).


Affected software

PHP

How to mitigate CVE-2003-0097

Install update from vendor's website.

PHP - update to 4.3.1

External References

Related Security Bulletins