PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 00:27
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/32768 - | |
References | () http://secunia.com/advisories/24089 - Vendor Advisory | |
References | () http://secunia.com/advisories/24419 - | |
References | () http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html - | |
References | () http://www.php.net/ChangeLog-5.php#5.2.1 - | |
References | () http://www.php.net/releases/5_2_1.php - | |
References | () http://www.securityfocus.com/bid/22496 - Patch | |
References | () http://www.trustix.org/errata/2007/0009/ - | |
References | () http://www.vupen.com/english/advisories/2007/0546 - |
Information
Published : 2007-02-13 23:28
Updated : 2024-11-21 00:27
NVD link : CVE-2007-0905
Mitre link : CVE-2007-0905
CVE.ORG link : CVE-2007-0905
JSON object : View
Products Affected
php
- php
trustix
- secure_linux
CWE