Information Exposure The advisory has been revoked - it doesn't affect any version of package apache/httpd  (opens in a new tab)


Threat Intelligence

EPSS
3.89% (90th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-APACHEHTTPD-3007432
  • published12 Jan 2022
  • disclosed23 Nov 2004
  • creditUnknown

Introduced: 23 Nov 2004

CVE-2004-0263  (opens in a new tab)
CWE-200  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Information Exposure. PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.

References