fopen_wrappers.c in PHP 4.4.0, and possibly other versions, does not properly restrict access to other directories when the open_basedir directive includes a trailing slash, which allows PHP scripts in one directory to access files in other directories whose names are substrings of the original directory.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-php/php.Upgrade dev-php/mod_php.Upgrade dev-php/php-cgi. | Oct 30, 2017 | Sep 26, 2005 |
| Php | — | Upgrade to PHP version 4.4.1 | Oct 1, 2012 | Sep 26, 2005 |
| Suse | — | Upgrade php4-sessionUpgrade php4-exifUpgrade php4-fastcgiUpgrade mod_php4-coreUpgrade php4-imapUpgrade apache-mod_php4Upgrade php4-sysvshmUpgrade php4-mysqlUpgrade apache2-mod_php4Upgrade mod_php4-servletUpgrade php4-pearUpgrade php4-devel | Dec 12, 2013 | Sep 26, 2005 |
| Ubuntu | — | Upgrade libapache2-mod-php4 | Nov 8, 2024 | Sep 26, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub