Lucene search

K
nvd[email protected]NVD:CVE-2010-1130
HistoryMar 26, 2010 - 8:30 p.m.

CVE-2010-1130

2010-03-2620:30:00
CWE-264
web.nvd.nist.gov
4

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

9.5

Confidence

High

EPSS

0.032

Percentile

91.2%

session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a … (dot dot).

Affected configurations

Nvd
Node
phpphpRange5.2.12
OR
phpphpMatch5.0.0
OR
phpphpMatch5.0.0beta1
OR
phpphpMatch5.0.0beta2
OR
phpphpMatch5.0.0beta3
OR
phpphpMatch5.0.0beta4
OR
phpphpMatch5.0.0rc1
OR
phpphpMatch5.0.0rc2
OR
phpphpMatch5.0.0rc3
OR
phpphpMatch5.0.1
OR
phpphpMatch5.0.2
OR
phpphpMatch5.0.3
OR
phpphpMatch5.0.4
OR
phpphpMatch5.0.5
OR
phpphpMatch5.1.0
OR
phpphpMatch5.1.1
OR
phpphpMatch5.1.2
OR
phpphpMatch5.1.3
OR
phpphpMatch5.1.4
OR
phpphpMatch5.1.5
OR
phpphpMatch5.1.6
OR
phpphpMatch5.2.0
OR
phpphpMatch5.2.1
OR
phpphpMatch5.2.2
OR
phpphpMatch5.2.3
OR
phpphpMatch5.2.4
OR
phpphpMatch5.2.5
OR
phpphpMatch5.2.6
OR
phpphpMatch5.2.7
OR
phpphpMatch5.2.8
OR
phpphpMatch5.2.9
OR
phpphpMatch5.2.10
OR
phpphpMatch5.2.11
OR
phpphpMatch5.2.13
OR
phpphpMatch5.3.1
VendorProductVersionCPE
phpphp*cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
phpphp5.0.0cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*
phpphp5.0.0cpe:2.3:a:php:php:5.0.0:beta1:*:*:*:*:*:*
phpphp5.0.0cpe:2.3:a:php:php:5.0.0:beta2:*:*:*:*:*:*
phpphp5.0.0cpe:2.3:a:php:php:5.0.0:beta3:*:*:*:*:*:*
phpphp5.0.0cpe:2.3:a:php:php:5.0.0:beta4:*:*:*:*:*:*
phpphp5.0.0cpe:2.3:a:php:php:5.0.0:rc1:*:*:*:*:*:*
phpphp5.0.0cpe:2.3:a:php:php:5.0.0:rc2:*:*:*:*:*:*
phpphp5.0.0cpe:2.3:a:php:php:5.0.0:rc3:*:*:*:*:*:*
phpphp5.0.1cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 351

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

9.5

Confidence

High

EPSS

0.032

Percentile

91.2%