Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-0754
Description:The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform differences in the stat structure, related to lack of a FILE_ATTRIBUTE_REPARSE_POINT check.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-0754
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12334
XForce ISS Database: php-splfileinfogettype-symlink(65429)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65429




© 1998-2025 E-Soft Inc. All rights reserved.