Description
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2007-1522)
Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35545)
Chamilo Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-38745)
WordPress Plugin Redux Framework Multiple Cross-Site Scripting Vulnerabilities (3.6.0.2)