Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2004-1064
Description:The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Test IDs: 1.3.6.1.4.1.25623.1.1.12.2005.99.2   1.3.6.1.4.1.25623.1.0.54306   1.3.6.1.4.1.25623.1.0.51928  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2004-1064
BugTraq ID: 11964
http://www.securityfocus.com/bid/11964
Bugtraq: 20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5 (Google Search)
http://www.securityfocus.com/archive/1/384545
Conectiva Linux advisory: CLA-2005:915
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000915
http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml
HPdes Security Advisory: HPSBMA01212
http://www.securityfocus.com/advisories/9028
http://www.mandriva.com/security/advisories?name=MDKSA-2004:151
http://www.mandriva.com/security/advisories?name=MDKSA-2005:072
http://www.hardened-php.net/advisories/012004.txt
https://www.ubuntu.com/usn/usn-99-1/
https://www.ubuntu.com/usn/usn-99-2/
XForce ISS Database: php-realpath-safemode-bypass(18512)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18512




© 1998-2025 E-Soft Inc. All rights reserved.