PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
Link | Tags |
---|---|
http://www.osvdb.org/3878 | vdb entry |
http://www.securityfocus.com/bid/9599 | vdb entry vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15072 | vdb entry |
http://security.gentoo.org/glsa/glsa-200402-01.xml | vendor advisory |