CVE Database
/

CVE-2006-6383

Back to search

CVE-2006-6383

Published: Dec 10, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path.

VendorProductVersions

n/a

n/a

affected
n/a

References

24022
third-party-advisory
x_refsource_SECUNIA
OpenPKG-SA-2007.010
vendor-advisory
x_refsource_OPENPKG
24514
third-party-advisory
x_refsource_SECUNIA
2000
third-party-advisory
x_refsource_SREASON
MDKSA-2007:038
vendor-advisory
x_refsource_MANDRIVA
SUSE-SA:2007:020
vendor-advisory
x_refsource_SUSE
21508
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now