CVE detail
CVE-2004-0263 — CVE-2004-0263
Published 2004-11-23 · Modified 2026-06-16 · Vendor apache · Product http_server · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0389
EPSS probability
exploitation probability, 30d
89.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References