CVE-2009-0754

low Apache
CVSS v3 Base Score
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N
EPSS Score
0.2%
Exploitation probability in 30 days
Top 63% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Confidentiality
None
Integrity
P
Availability
None
Published: March 3, 2009 (6281 days ago)
Last Modified: April 23, 2026
Vendor: Apache
Source: NVD

Description

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CWE

CWE-134

Affected Products

php php

References