Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-938g-fg7w-7c7v

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

EPSS

Процентиль: 77%
0.01104
Низкий

Дефекты

CWE-862

Связанные уязвимости

ubuntu
около 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

nvd
около 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

debian
около 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/str ...

EPSS

Процентиль: 77%
0.01104
Низкий

Дефекты

CWE-862