PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506 - | |
References | () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137 - | |
References | () http://lists.suse.com/archive/suse-security-announce/2006-Oct/0002.html - | |
References | () http://secunia.com/advisories/22282 - | |
References | () http://secunia.com/advisories/22331 - | |
References | () http://secunia.com/advisories/22338 - | |
References | () http://secunia.com/advisories/22424 - | |
References | () http://secunia.com/advisories/25423 - | |
References | () http://secunia.com/advisories/25850 - | |
References | () http://securityreason.com/achievement_securityalert/42 - Exploit, Patch | |
References | () http://securityreason.com/securityalert/1519 - | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2006:185 - | |
References | () http://www.securityfocus.com/archive/1/445712/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/445882/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/448953/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/19933 - Exploit | |
References | () http://www.turbolinux.com/security/2006/TLSA-2006-38.txt - | |
References | () http://www.ubuntu.com/usn/usn-362-1 - | |
References | () http://www.vupen.com/english/advisories/2007/1991 - | |
References | () http://www.vupen.com/english/advisories/2007/2374 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/28853 - |
Information
Published : 2006-09-12 16:07
Updated : 2024-11-21 00:16
NVD link : CVE-2006-4625
Mitre link : CVE-2006-4625
CVE.ORG link : CVE-2006-4625
JSON object : View
Products Affected
php
- php
CWE