The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP applications that contain a directory traversal vulnerability in require or include statements, but are otherwise protected by the magic_quotes_gpc mechanism. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Php | — | Apply OS X security update 2005-001 | Dec 16, 2011 | Jan 10, 2005 |
| Gentoo Linux | — | Upgrade dev-php/php.Upgrade dev-php/mod_php.Upgrade dev-php/php-cgi. | Oct 30, 2017 | Jan 10, 2005 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Jan 10, 2005 |
| Php | — | Upgrade to PHP version 4.3.10Upgrade to PHP version 5.0.3 | Oct 1, 2012 | Jan 10, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub