Back to search
CVE-2007-4825
Published: Sep 12, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.php.net/ChangeLog-5.php#5.2.5
x_refsource_CONFIRM
20070910 Re: PHP <=5.2.4 open_basedir bypass & code exec & denial of service
mailing-list
x_refsource_BUGTRAQ
45902
vdb-entry
x_refsource_OSVDB
SUSE-SA:2008:004
vendor-advisory
x_refsource_SUSE
28658
third-party-advisory
x_refsource_SECUNIA
3119
third-party-advisory
x_refsource_SREASON
GLSA-200710-02
vendor-advisory
x_refsource_GENTOO
20070910 /* PHP <=5.2.4 open_basedir bypass & code exec & denial of service errata ... working on windows too .. */
mailing-list
x_refsource_BUGTRAQ
http://www.php.net/releases/5_2_5.php
x_refsource_CONFIRM
20070910 PHP <=5.2.4 open_basedir bypass & code exec & denial of service
mailing-list
x_refsource_BUGTRAQ
php-dl-security-bypass(36528)
vdb-entry
x_refsource_XF
27102
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now