AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2009-0754

LOW · CVSS 2.1 EPSS 0.95%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-03-03 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2009-0754
Severity
LOW
CVSS
2.1
EPSS
0.95%
Apache

Original Filing — NVD Description

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.