Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-4825
Description:Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-4825
Bugtraq: 20070910 /* PHP <=5.2.4 open_basedir bypass & code exec & denial of service errata ... working on windows too .. */ (Google Search)
http://www.securityfocus.com/archive/1/478988/100/0/threaded
Bugtraq: 20070910 PHP <=5.2.4 open_basedir bypass & code exec & denial of service (Google Search)
http://www.securityfocus.com/archive/1/478985/100/0/threaded
Bugtraq: 20070910 Re: PHP <=5.2.4 open_basedir bypass & code exec & denial of service (Google Search)
http://www.securityfocus.com/archive/1/478989/100/0/threaded
http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml
http://osvdb.org/45902
http://secunia.com/advisories/27102
http://secunia.com/advisories/28658
http://securityreason.com/securityalert/3119
SuSE Security Announcement: SUSE-SA:2008:004 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html
XForce ISS Database: php-dl-security-bypass(36528)
https://exchange.xforce.ibmcloud.com/vulnerabilities/36528




© 1998-2025 E-Soft Inc. All rights reserved.