Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-4481
HistoryAug 31, 2006 - 12:00 a.m.

CVE-2006-4481

2006-08-3100:00:00
ubuntu.com
ubuntu.com
11

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.13

Percentile

95.5%

The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do
not check for the safe_mode and open_basedir settings, which allows local
users to bypass the settings. NOTE: the error_log function is covered by
CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchphp5<ย 5.1.2-1ubuntu3.9UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.13

Percentile

95.5%