// For flags

CVE-2003-1307

Apache 2.0.4x mod_php - File Descriptor Leakage

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

6
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2003-12-26 First Exploit
  • 2003-12-31 CVE Published
  • 2006-10-23 CVE Reserved
  • 2024-06-28 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0
Search vendor "Apache" for product "Http Server" and version "2.0"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.9
Search vendor "Apache" for product "Http Server" and version "2.0.9"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.28
Search vendor "Apache" for product "Http Server" and version "2.0.28"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.28
Search vendor "Apache" for product "Http Server" and version "2.0.28"
beta
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.28
Search vendor "Apache" for product "Http Server" and version "2.0.28"
beta, win32
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.32
Search vendor "Apache" for product "Http Server" and version "2.0.32"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.32
Search vendor "Apache" for product "Http Server" and version "2.0.32"
beta, win32
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.34
Search vendor "Apache" for product "Http Server" and version "2.0.34"
beta, win32
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.35
Search vendor "Apache" for product "Http Server" and version "2.0.35"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.36
Search vendor "Apache" for product "Http Server" and version "2.0.36"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.37
Search vendor "Apache" for product "Http Server" and version "2.0.37"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.38
Search vendor "Apache" for product "Http Server" and version "2.0.38"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.39
Search vendor "Apache" for product "Http Server" and version "2.0.39"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.40
Search vendor "Apache" for product "Http Server" and version "2.0.40"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.41
Search vendor "Apache" for product "Http Server" and version "2.0.41"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.42
Search vendor "Apache" for product "Http Server" and version "2.0.42"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.43
Search vendor "Apache" for product "Http Server" and version "2.0.43"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.44
Search vendor "Apache" for product "Http Server" and version "2.0.44"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.45
Search vendor "Apache" for product "Http Server" and version "2.0.45"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.46
Search vendor "Apache" for product "Http Server" and version "2.0.46"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.46
Search vendor "Apache" for product "Http Server" and version "2.0.46"
win32
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.47
Search vendor "Apache" for product "Http Server" and version "2.0.47"
-
Affected
Apache
Search vendor "Apache"
Http Server
Search vendor "Apache" for product "Http Server"
2.0.48
Search vendor "Apache" for product "Http Server" and version "2.0.48"
-
Affected