Description
Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).
Affected PHP version 4.3.0.
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
WordPress Plugin Simple File Downloader Cross-Site Scripting (1.0.4)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2016-0219)
WordPress Plugin Permalink Manager Lite Unspecified Vulnerability (2.2.13.1)
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-24407)