Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-4483

Опубликовано: 31 авг. 2006
Источник: ubuntu
Приоритет: untriaged
CVSS2: 9.3

Описание

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

РелизСтатусПримечание
dapper

released

5.1.2-1ubuntu3.9
devel

not-affected

edgy

released

5.1.6-1ubuntu2.6
feisty

released

5.2.1-0ubuntu1.4
upstream

needs-triage

Показывать по

Ссылки на источники

9.3 Critical

CVSS2

Связанные уязвимости

nvd
почти 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

debian
почти 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/str ...

github
около 3 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

9.3 Critical

CVSS2