9.3
CVSSv2

CVE-2006-4483

Published: 31/08/2006 Updated: 19/07/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP prior to 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows malicious users to perform unauthorized actions, possibly related to the realpath cache.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php