The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade php5-cliUpgrade php5-dtcUpgrade php4-cliUpgrade php5-hordeUpgrade php4-dtcUpgrade php4-hordeUpgrade php4-nmsUpgrade mod_php5Upgrade php5-nmsUpgrade php5-cgiUpgrade php4-cgiUpgrade mod_php4Upgrade php5Upgrade php4 | Dec 10, 2025 | Sep 13, 2006 |
| Php | — | Upgrade to PHP version 5.1.5 | Oct 1, 2012 | Aug 31, 2006 |
| Ubuntu | — | Upgrade php5-curlUpgrade php5-cgiUpgrade php5-cliUpgrade libapache2-mod-php5Upgrade libapache2-mod-php4Upgrade php4-cgiUpgrade php4-cli | Nov 8, 2024 | Aug 31, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub