Vulnerability & Exploit Database

Back to search

PHP 'file_exists(),' 'imap_open(),' and 'imap_reopen()' Function Safe Mode Bypass Vulnerability

Severity CVSS Published Added Modified
7 (AV:L/AC:L/Au:N/C:C/I:C/A:C) August 18, 2006 August 21, 2006 February 13, 2015

Description

The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.

Scan For This Vulnerability

Use our top-rated tool to discover, prioritize, and remediate your vulnerabilities

 Free InsightVM Trial

References

Solution

php-upgrade-5_1_5

Related Vulnerabilities