CVE Database
/

CVE-2006-2825

Back to search

CVE-2006-2825

Published: Jun 5, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive.

VendorProductVersions

n/a

n/a

affected
n/a

References

20060520 cPanel OpenBaseDir Bypass
mailing-list
x_refsource_BUGTRAQ
31835
vdb-entry
x_refsource_OSVDB
1039
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now