Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Php | — | Upgrade macOS to the latest version | Dec 16, 2011 | Jun 19, 2008 |
| Freebsd | — | Upgrade php5 | Dec 10, 2025 | Jun 22, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Jun 19, 2008 |
| Php | — | Upgrade to PHP version 5.2.7 | Oct 1, 2012 | Jun 19, 2008 |
| Php Fixed Security Issues | — | Upgrade to PHP version 5.2.7 | Sep 16, 2010 | Jun 20, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub