7.5 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
0.018 Low
EPSS
Percentile
88.1%
ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not
validate the relationship between the soap.wsdl_cache_dir directive and the
open_basedir directive, which allows remote attackers to bypass intended
access restrictions by triggering the creation of cached SOAP WSDL files in
an arbitrary directory.
Author | Note |
---|---|
mdeslaur | we do not support the use of open_basedir, marking as ignored |