CVE-2003-0863
PHP 4.3.x - Info Disclosure
Title source: llmDescription
The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Michal Krause · phplocalphp
https://www.exploit-db.com/exploits/22911
References (1)
Scores
EPSS
0.0299
EPSS Percentile
86.6%
Details
Status
published
Products (3)
php/php
4.3.0
php/php
4.3.1
php/php
4.3.2
Published
Nov 17, 2003
Tracked Since
Feb 18, 2026