2.1
CVSSv2

CVE-2009-0754

Published: 03/03/2009 Updated: 03/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.1.6

php php 4.4.4

Vendor Advisories

Synopsis Moderate: php security update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix several security issues are now available forRed Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Descriptio ...
It was discovered that PHP did not sanitize certain error messages when display_errors is enabled, which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attac ...
Debian Bug report logs - #523028 CVE-2008-5814: XSS vulnerability in PHP <= 527 Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 7 Apr ...
Debian Bug report logs - #523049 CVE-2009-0754: mbstringfunc_overload setting leakage across vhosts Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> D ...
Several remote vulnerabilities have been discovered in the PHP 5 hypertext preprocessor The Common Vulnerabilities and Exposures project identifies the following problems The following four vulnerabilities have already been fixed in the stable (lenny) version of php5 prior to the release of lenny This update now addresses them for etch (oldstab ...

Exploits

source: wwwsecurityfocuscom/bid/33542/info PHP is prone to a denial-of-service vulnerability because it fails to limit global scope for certain settings relating to Unicode text operations Attackers can exploit this issue to crash the affected webserver, denying service to legitimate users <?php $v = 'Òîâà å òåñò| ...