CVE-2006-3011
טרם דורגה
תיאור (מקור, אנגלית)
The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.
מדדים
- EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-23/9/2026
- CWE
- CWE-264
מוצרים מושפעים
php: php
קישורים
- http://secunia.com/advisories/20818 Vendor Advisory
- http://secunia.com/advisories/21050 Vendor Advisory
- http://secunia.com/advisories/21125 Vendor Advisory
- http://secunia.com/advisories/21546 PatchVendor Advisory
- http://www.vupen.com/english/advisories/2006/2523 Vendor Advisory
- http://secunia.com/advisories/20818 Vendor Advisory
- http://secunia.com/advisories/21050 Vendor Advisory
- http://secunia.com/advisories/21125 Vendor Advisory
- http://secunia.com/advisories/21546 PatchVendor Advisory
- http://www.vupen.com/english/advisories/2006/2523 Vendor Advisory