7.2
CVSSv2

CVE-2014-0185

Published: 06/05/2014 Updated: 16/08/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP prior to 5.4.28 and 5.5.x prior to 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

Vendor Advisories

An improvement was made for PHP FPM environments ...
Several security issues were fixed in PHP ...
Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development: CVE-2014-0185 The default PHP FPM socket permission has been changed from 0666 to 0660 to mitigate a security vulnerability (CVE-2014-0185) in PHP FPM that allowed any local user to run a PHP code under the ...
sapi/fpm/fpm/fpm_unixc in the FastCGI Process Manager (FPM) in PHP before 5428 and 55x before 5512 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client ...