PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 4.4.5Upgrade to PHP version 5.2.0 | Oct 1, 2012 | Sep 12, 2006 |
| Suse | — | Upgrade php4-pgsqlUpgrade php4-pearUpgrade apache2-mod_php4Upgrade php4-imapUpgrade php4-curlUpgrade php4-gdUpgrade apache-mod_php4Upgrade mod_php4-coreUpgrade php4-mysqlUpgrade php4-sysvshmUpgrade php4-wddxUpgrade php4-fastcgiUpgrade php4-mbstringUpgrade php4-develUpgrade php4-sessionUpgrade php4-exifUpgrade mod_php4-servletUpgrade php4-recode | Feb 17, 2015 | Sep 12, 2006 |
| Ubuntu | — | Upgrade php4-cliUpgrade libapache2-mod-php5Upgrade php5-cgiUpgrade php5-cliUpgrade libapache2-mod-php4Upgrade php4-cgi | Nov 8, 2024 | Sep 12, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub