7.5
CVSSv2

CVE-2007-0905

Published: 13/02/2007 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP prior to 5.2.1 allows malicious users to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 3.0

php php 3.0.1

php php 3.0.16

php php 3.0.17

php php 3.0.18

php php 3.0.8

php php 3.0.9

php php 4.0.3

php php 4.0.4

php php 4.1.1

php php 4.1.2

php php 4.3.1

php php 4.3.10

php php 4.3.7

php php 4.3.8

php php 5.0.1

php php 5.0.2

php php 5.1.0

php php 5.1.1

php php 3.0.10

php php 3.0.11

php php 3.0.2

php php 3.0.3

php php 4.0

php php 4.0.1

php php 4.0.5

php php 4.0.6

php php 4.2.0

php php 4.2.1

php php 4.3.11

php php 4.3.2

php php 4.3.9

php php 4.4.0

php php 5.0.3

php php 5.0.4

php php 5.1.2

php php 5.1.3

php php 3.0.12

php php 3.0.13

php php 3.0.4

php php 3.0.5

php php 4.0.7

php php 4.2.2

php php 4.2.3

php php 4.3.3

php php 4.3.4

php php 4.4.1

php php 4.4.2

php php 4.4.3

php php 5.0.5

php php 5.0

php php 5.1.4

php php 5.1.5

php php 3.0.14

php php 3.0.15

php php 3.0.6

php php 3.0.7

php php 4.0.2

php php 4.1.0

php php 4.2

php php 4.3.0

php php 4.3.5

php php 4.3.6

php php 4.4.4

php php 5.0.0

php php 5.1.6

php php 5.2.0

trustix secure linux 2.2

trustix secure linux 3.0

Vendor Advisories

Debian Bug report logs - #410561 php5: multiple security issues fixed in php 521 Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Sun, 11 Feb 2007 19:48:02 UTC S ...