The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 5.1.5Upgrade to PHP version 4.4.4 | Oct 1, 2012 | Jun 26, 2006 |
| Ubuntu | — | Upgrade php5-cgiUpgrade php5-cliUpgrade php5-curlUpgrade php4-cliUpgrade libapache2-mod-php4Upgrade libapache2-mod-php5Upgrade php4-cgi | Nov 8, 2024 | Jun 26, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub