9.3
CVSSv2

CVE-2006-1017

Published: 07/03/2006 Updated: 30/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The c-client library 2000, 2001, or 2004 for PHP prior to 4.4.4 and 5.x prior to 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote malicious users to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 3.0

php php 3.0.1

php php 3.0.17

php php 3.0.18

php php 3.0.8

php php 3.0.9

php php 4.0.3

php php 4.0.4

php php 4.0.5

php php 4.1.1

php php 4.1.2

php php 4.3.1

php php 4.3.10

php php 4.3.8

php php 4.3.9

php php 5.0.0

php php 5.0.3

php php 5.0.4

php php 5.1.3

php php 5.1.4

php php 3.0.13

php php 3.0.14

php php 3.0.4

php php 3.0.5

php php 4.0.1

php php 4.0.7

php php 4.2.2

php php 4.2.3

php php 4.3.3

php php 4.3.4

php php 4.4.2

php php 4.4.3

php php 5.0

php php 5.1.0

php php 3.0.10

php php 3.0.11

php php 3.0.12

php php 3.0.2

php php 3.0.3

php php 4.0.0

php php 4.0.6

php php 4.2.0

php php 4.2.1

php php 4.3.11

php php 4.3.2

php php 4.4.0

php php 4.4.1

php php 5.0.5

php php 3.0.15

php php 3.0.16

php php 3.0.6

php php 3.0.7

php php 4.0.2

php php 4.1.0

php php 4.2

php php 4.3.0

php php 4.3.5

php php 4.3.6

php php 4.3.7

php php 5.0.1

php php 5.0.2

php php 5.1.1

php php 5.1.2