6.8

CVE-2009-3558

Exploit

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

Data is provided by the National Vulnerability Database (NVD)
PhpPhp Version <= 5.2.10
   PhpPhp Version <= 5.2.10
PhpPhp Version1.0
   PhpPhp Version1.0
PhpPhp Version2.0
   PhpPhp Version2.0
PhpPhp Version2.0b10
   PhpPhp Version2.0b10
PhpPhp Version3.0
   PhpPhp Version3.0
PhpPhp Version3.0.1
   PhpPhp Version3.0.1
PhpPhp Version3.0.2
   PhpPhp Version3.0.2
PhpPhp Version3.0.3
   PhpPhp Version3.0.3
PhpPhp Version3.0.4
   PhpPhp Version3.0.4
PhpPhp Version3.0.5
   PhpPhp Version3.0.5
PhpPhp Version3.0.6
   PhpPhp Version3.0.6
PhpPhp Version3.0.7
   PhpPhp Version3.0.7
PhpPhp Version3.0.8
   PhpPhp Version3.0.8
PhpPhp Version3.0.9
   PhpPhp Version3.0.9
PhpPhp Version3.0.10
   PhpPhp Version3.0.10
PhpPhp Version3.0.11
   PhpPhp Version3.0.11
PhpPhp Version3.0.12
   PhpPhp Version3.0.12
PhpPhp Version3.0.13
   PhpPhp Version3.0.13
PhpPhp Version3.0.14
   PhpPhp Version3.0.14
PhpPhp Version3.0.15
   PhpPhp Version3.0.15
PhpPhp Version3.0.16
   PhpPhp Version3.0.16
PhpPhp Version3.0.17
   PhpPhp Version3.0.17
PhpPhp Version3.0.18
   PhpPhp Version3.0.18
PhpPhp Version4.0
   PhpPhp Version4.0
PhpPhp Version4.0 Updatebeta_4_patch1
   PhpPhp Version4.0 Updatebeta_4_patch1
PhpPhp Version4.0 Updatebeta1
   PhpPhp Version4.0 Updatebeta1
PhpPhp Version4.0 Updatebeta2
   PhpPhp Version4.0 Updatebeta2
PhpPhp Version4.0 Updatebeta3
   PhpPhp Version4.0 Updatebeta3
PhpPhp Version4.0 Updatebeta4
   PhpPhp Version4.0 Updatebeta4
PhpPhp Version4.0.0
   PhpPhp Version4.0.0
PhpPhp Version4.0.1
   PhpPhp Version4.0.1
PhpPhp Version4.0.2
   PhpPhp Version4.0.2
PhpPhp Version4.0.3
   PhpPhp Version4.0.3
PhpPhp Version4.0.4
   PhpPhp Version4.0.4
PhpPhp Version4.0.5
   PhpPhp Version4.0.5
PhpPhp Version4.0.6
   PhpPhp Version4.0.6
PhpPhp Version4.0.7
   PhpPhp Version4.0.7
PhpPhp Version4.1.0
   PhpPhp Version4.1.0
PhpPhp Version4.1.1
   PhpPhp Version4.1.1
PhpPhp Version4.1.2
   PhpPhp Version4.1.2
PhpPhp Version4.2.0
   PhpPhp Version4.2.0
PhpPhp Version4.2.1
   PhpPhp Version4.2.1
PhpPhp Version4.2.2
   PhpPhp Version4.2.2
PhpPhp Version4.2.3
   PhpPhp Version4.2.3
PhpPhp Version4.3.0
   PhpPhp Version4.3.0
PhpPhp Version4.3.1
   PhpPhp Version4.3.1
PhpPhp Version4.3.2
   PhpPhp Version4.3.2
PhpPhp Version4.3.7
   PhpPhp Version4.3.7
PhpPhp Version4.3.10
   PhpPhp Version4.3.10
PhpPhp Version4.3.11
   PhpPhp Version4.3.11
PhpPhp Version4.4.2
   PhpPhp Version4.4.2
PhpPhp Version4.4.7
   PhpPhp Version4.4.7
PhpPhp Version4.4.8
   PhpPhp Version4.4.8
PhpPhp Version5.0.0
   PhpPhp Version5.0.0
PhpPhp Version5.0.0 Updatebeta4
   PhpPhp Version5.0.0 Updatebeta4
PhpPhp Version5.0.3
   PhpPhp Version5.0.3
PhpPhp Version5.1.1
   PhpPhp Version5.1.1
PhpPhp Version5.2.1
   PhpPhp Version5.2.1
PhpPhp Version5.2.5
   PhpPhp Version5.2.5
PhpPhp Version5.2.6
   PhpPhp Version5.2.6
PhpPhp Version5.3.0
   PhpPhp Version5.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.44% 0.886
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P