Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-0108

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2001-0108
Last Modified 10 Sep 2008 03:07:15
Published 12 Mar 2001 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2001-0108

Summary

PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.

Vulnerable Systems

Operating System

  • Mandrakesoft Mandrake Linux 7.2

Application

  • Php 4.0

  • Php 4.0.1

  • Php 4.0.3

  • Php 4.0.4


References

BID - 2206

XF - php-htaccess-unauth-access(5940)

REDHAT - RHSA-2000:136

MANDRAKE - MDKSA-2001:013

DEBIAN - DSA-020

BUGTRAQ - 20010112 PHP Security Advisory - Apache Module bugs

CONECTIVA - CLA-2001:373


Last Updated: 27 May 2016 10:36:08