Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-938g-fg7w-7c7v

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

EPSS

Процентиль: 82%
0.01805
Низкий

Дефекты

CWE-862

Связанные уязвимости

ubuntu
почти 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

nvd
почти 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

debian
почти 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/str ...

EPSS

Процентиль: 82%
0.01805
Низкий

Дефекты

CWE-862