• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2006-3011
  1. CVEs

CVE-2006-3011

medium
  • Information
  • CPEs
  • Plugins

Description

The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.

References

http://cvs.php.net/viewvc.cgi/php-src/ext/standard/basic_functions.c?diff_format=u&view=log&pathrev=PHP_4_4

http://cvs.php.net/viewvc.cgi/php-src/ext/standard/basic_functions.c?r1=1.543.2.51.2.9&r2=1.543.2.51.2.10&pathrev=PHP_4_4&diff_format=u

http://secunia.com/advisories/20818

http://secunia.com/advisories/21050

http://secunia.com/advisories/21125

http://secunia.com/advisories/21546

http://securityreason.com/achievement_securityalert/41

http://securityreason.com/securityalert/1129

http://securitytracker.com/id?1016377

http://www.mandriva.com/security/advisories?name=MDKSA-2006:122

http://www.osvdb.org/26827

http://www.php.net/release_5_1_5.php

http://www.securityfocus.com/bid/18645

http://www.ubuntu.com/usn/usn-320-1

http://www.vupen.com/english/advisories/2006/2523

https://exchange.xforce.ibmcloud.com/vulnerabilities/27414

Details

Source: MITRE

Published: 2006-06-26

Updated: 2017-07-20

Type: CWE-264

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance