5
CVSSv2

CVE-2008-2666

Published: 20/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in PHP 5.2.6 and previous versions allow context-dependent malicious users to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.0.0

php php 5.0.1

php php 5.1.0

php php 5.1.1

php php 5.2.1

php php 5.2.2

php php 5.0.2

php php 5.0.3

php php 5.1.2

php php 5.1.3

php php 5.2.3

php php 5.2.4

php php 5.0

php php 5.1.6

php php 5.2.0

php php 5.0.4

php php 5.0.5

php php 5.1.4

php php 5.1.5

php php 5.2.5

php php

Exploits

source: wwwsecurityfocuscom/bid/29796/info PHP is prone to multiple 'safe_mode' restriction-bypass vulnerabilities Successful exploits could allow an attacker to determine the presence of files in unauthorized locations; other attacks are also possible Exploiting these issues allows attackers to obtain sensitive data that could be used ...