The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade php5-dbaUpgrade php4-dba | Dec 10, 2025 | May 16, 2009 |
| Php | — | Upgrade to PHP version 5.2.7Upgrade to PHP version 5.0.0 | Oct 1, 2012 | Aug 25, 2009 |
| Ubuntu | — | Upgrade libapache2-mod-php5Upgrade php5-cgiUpgrade php5-cli | Nov 8, 2024 | Aug 25, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub