7.5
CVSSv2

CVE-2013-1635

Published: 06/03/2013 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ext/soap/soap.c in PHP prior to 5.3.22 and 5.4.x prior to 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote malicious users to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.3.9

php php 4.4.9

php php 3.0

php php

php php 5.2.9

php php 4.0

php php 3.0.5

php php 3.0.11

php php 5.3.10

php php 5.1.5

php php 5.3.6

php php 5.3.9

php php 5.1.2

php php 5.3.1

php php 4.2.0

php php 5.1.1

php php 3.0.1

php php 5.3.18

php php 5.2.14

php php 3.0.2

php php 4.4.4

php php 5.0.0

php php 4.1.0

php php 5.1.6

php php 5.2.16

php php 4.3.4

php php 4.0.4

php php 4.3.0

php php 4.0.5

php php 5.3.15

php php 5.3.8

php php 5.2.7

php php 5.2.2

php php 3.0.8

php php 5.0.5

php php 4.3.6

php php 3.0.13

php php 5.0.1

php php 5.1.4

php php 5.3.14

php php 5.2.5

php php 4.3.7

php php 5.0.4

php php 4.2.2

php php 4.4.2

php php 5.2.12

php php 3.0.7

php php 4.3.2

php php 5.3.20

php php 4.3.11

php php 4.0.0

php php 3.0.6

php php 3.0.17

php php 4.0.7

php php 4.0.2

php php 4.3.3

php php 2.0

php php 4.1.1

php php 5.3.12

php php 3.0.15

php php 3.0.16

php php 5.2.11

php php 5.2.6

php php 5.2.17

php php 5.3.0

php php 4.4.3

php php 5.2.3

php php 5.3.3

php php 5.0.3

php php 3.0.10

php php 5.3.7

php php 3.0.4

php php 4.2.3

php php 5.1.0

php php 4.4.5

php php 5.2.13

php php 2.0b10

php php 4.4.8

php php 4.0.6

php php 5.2.0

php php 5.2.4

php php 5.3.11

php php 4.1.2

php php 5.3.17

php php 5.3.2

php php 5.3.4

php php 5.3.16

php php 4.3.1

php php 5.1.3

php php 3.0.18

php php 4.4.0

php php 5.2.10

php php 4.3.10

php php 4.2.1

php php 4.0.1

php php 1.0

php php 5.0.2

php php 4.4.6

php php 3.0.12

php php 5.2.15

php php 5.3.5

php php 4.4.1

php php 5.2.1

php php 5.3.13

php php 4.0.3

php php 3.0.14

php php 3.0.9

php php 3.0.3

php php 5.3.19

php php 4.3.8

php php 4.3.5

php php 5.2.8

php php 4.4.7

php php 5.4.12

php php 5.4.8

php php 5.4.9

php php 5.4.11

php php 5.4.10

php php 5.4.2

php php 5.4.5

php php 5.4.6

php php 5.4.0

php php 5.4.3

php php 5.4.1

php php 5.4.7

php php 5.4.4

Vendor Advisories

Debian Bug report logs - #702221 php5: CVE-2013-1635 CVE-2013-1643 Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 4 Mar 2013 09:42:01 UTC Severity: gra ...
Several vulnerabilities have been discovered in PHP, the web scripting language The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-1635 If a PHP application accepted untrusted SOAP object input remotely from clients, an attacker could read system files readable for the webserver CVE-2013-1643 ...