The (1) session_save_path, (2) ini_set, and (3) error_log functions in PHP 4.4.7 and earlier, and PHP 5 5.2.3 and earlier, when invoked from a .htaccess file, allow remote attackers to bypass safe_mode and open_basedir restrictions and possibly execute arbitrary commands, as demonstrated using (a) php_value, (b) php_flag, and (c) directives in .htaccess.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Php | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Jun 29, 2007 |
| Freebsd | — | Upgrade php5Upgrade php4 | Dec 10, 2025 | Sep 11, 2007 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Jun 29, 2007 |
| Hpux | — | Update hpuxwsAPACHE to the latest version | Aug 11, 2017 | Jun 29, 2007 |
| Php | — | Upgrade to PHP version 4.4.8Upgrade to PHP version 5.2.4 | Oct 1, 2012 | Jun 29, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub