6.8

CVE-2007-3378

Exploit

The (1) session_save_path, (2) ini_set, and (3) error_log functions in PHP 4.4.7 and earlier, and PHP 5 5.2.3 and earlier, when invoked from a .htaccess file, allow remote attackers to bypass safe_mode and open_basedir restrictions and possibly execute arbitrary commands, as demonstrated using (a) php_value, (b) php_flag, and (c) directives in .htaccess.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpPhp Version >= 4.0.0 <= 4.4.7
PhpPhp Version >= 5.0.0 <= 5.2.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.2% 0.866
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
http://www.vupen.com/english/advisories/2008/0924/references
Third Party Advisory
Permissions Required
http://www.php.net/ChangeLog-4.php
Patch
Vendor Advisory
http://www.vupen.com/english/advisories/2008/0059
Third Party Advisory
Permissions Required
http://www.vupen.com/english/advisories/2008/0398
Third Party Advisory
Permissions Required
http://securityreason.com/securityalert/2831
Third Party Advisory
Exploit
http://securityreason.com/securityalert/3389
Third Party Advisory
Exploit
http://www.securityfocus.com/bid/24661
Patch
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/25498
Patch
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2007/3023
Third Party Advisory
Permissions Required