CVE-2003-0863

NameCVE-2003-0863
DescriptionThe php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

php4, this bug appears not to have been fixed.
submitted to BTS on libapache-mod-php4
developer claims there is no problem

Search for package or bug name: Reporting problems