![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2006-3011 |
Description: | The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-3011 BugTraq ID: 18645 http://www.securityfocus.com/bid/18645 http://www.mandriva.com/security/advisories?name=MDKSA-2006:122 http://www.osvdb.org/26827 http://securitytracker.com/id?1016377 http://secunia.com/advisories/20818 http://secunia.com/advisories/21050 http://secunia.com/advisories/21125 http://secunia.com/advisories/21546 http://securityreason.com/securityalert/1129 http://securityreason.com/achievement_securityalert/41 http://www.ubuntu.com/usn/usn-320-1 http://www.vupen.com/english/advisories/2006/2523 XForce ISS Database: php-errorlog-safe-mode-bypass(27414) https://exchange.xforce.ibmcloud.com/vulnerabilities/27414 |