CVE Database
/

CVE-2008-1734

Back to search

CVE-2008-1734

Published: Apr 18, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.

VendorProductVersions

n/a

n/a

affected
n/a

References

28844
vdb-entry
x_refsource_BID
phptoolkit-phpselect-dos(41928)
vdb-entry
x_refsource_XF
GLSA-200804-19
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now