The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade php5-nmsUpgrade php4-hordeUpgrade php4-nmsUpgrade php5Upgrade php4-dtcUpgrade php5-cliUpgrade mod_php5Upgrade php4-cgiUpgrade php5-cgiUpgrade php5-dtcUpgrade php4-cliUpgrade php4Upgrade php5-hordeUpgrade mod_php4 | Dec 10, 2025 | Sep 13, 2006 |
| Php | — | Upgrade to PHP version 5.1.5 | Oct 1, 2012 | Aug 31, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub