CVE-2009-0754
Last modified
CVE-2009-0754 is a vulnerability of currently unknown severity. PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | 4.4.4 |
| Php | Php | 5.1.6 |
References
- http://bugs.php.net/bug.php?id=27421Exploit, Vendor Advisory
- http://bugs.php.net/bug.php?id=27421Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0754?
How severe is CVE-2009-0754?
How do I fix CVE-2009-0754?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0748The ext4_fill_super function in fs/ext4/super.c in the Linux…
- CVE-2009-0749Use-after-free vulnerability in the GIFReadNextExtension fun…7.8
- CVE-2009-0750SQL injection vulnerability in login.php in the smNews examp…
- CVE-2009-0751Yaws before 1.80 allows remote attackers to cause a denial o…
- CVE-2009-0752Unspecified vulnerability in Movable Type Pro and Community …
- CVE-2009-0753Absolute path traversal vulnerability in MLDonkey 2.8.4 thro…
- CVE-2009-0755The FormWidgetChoice::loadDefaults function in Poppler befor…
- CVE-2009-0756The JBIG2Stream::readSymbolDictSeg function in Poppler befor…
- CVE-2009-0757Multiple buffer overflows in GNU MPFR 2.4.0 allow context-de…
- CVE-2009-0758The originates_from_local_legacy_unicast_socket function in …
- CVE-2009-0759Multiple CRLF injection vulnerabilities in webadmin in ZNC b…
- CVE-2009-0760Team Board 1.x and 2.x stores sensitive information under th…
Are you affected by CVE-2009-0754?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
