Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-0448

Опубликовано: 24 мая 2007
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01823
Низкий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
около 18 лет назад

The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.

debian
около 18 лет назад

The fopen function in PHP 5.2.0 does not properly handle invalid URI h ...

github
около 3 лет назад

The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.

EPSS

Процентиль: 82%
0.01823
Низкий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other