CVE
- Id
- 14595
- CVE No.
- CVE-2005-3389
- Status
- Candidate
- Description
- The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.
- Phase
- Assigned (20051101)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
111105 | 14595 | CVE-2005-3389 | BUGTRAQ:20051031 Advisory 19/2005: PHP register_globals Activation Vulnerability in parse_str() | View |
111106 | 14595 | CVE-2005-3389 | URL:http://www.securityfocus.com/archive/1/415291 | View |
111107 | 14595 | CVE-2005-3389 | MISC:http://www.hardened-php.net/advisory_192005.78.html | View |
111108 | 14595 | CVE-2005-3389 | CONFIRM:http://www.php.net/release_4_4_1.php | View |
111109 | 14595 | CVE-2005-3389 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2006-037.htm | View |
111110 | 14595 | CVE-2005-3389 | FEDORA:FLSA:166943 | View |
111111 | 14595 | CVE-2005-3389 | URL:http://www.fedoralegacy.org/updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.html | View |
111112 | 14595 | CVE-2005-3389 | GENTOO:GLSA-200511-08 | View |
111113 | 14595 | CVE-2005-3389 | URL:http://www.gentoo.org/security/en/glsa/glsa-200511-08.xml | View |
111114 | 14595 | CVE-2005-3389 | HP:HPSBMA02159 | View |
111115 | 14595 | CVE-2005-3389 | URL:http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522 | View |
111116 | 14595 | CVE-2005-3389 | HP:SSRT061238 | View |
111117 | 14595 | CVE-2005-3389 | URL:http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522 | View |
111118 | 14595 | CVE-2005-3389 | MANDRIVA:MDKSA-2005:213 | View |
111119 | 14595 | CVE-2005-3389 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:213 | View |
111120 | 14595 | CVE-2005-3389 | OPENPKG:OpenPKG-SA-2005.027 | View |
111121 | 14595 | CVE-2005-3389 | URL:http://www.openpkg.org/security/OpenPKG-SA-2005.027-php.html | View |
111122 | 14595 | CVE-2005-3389 | REDHAT:RHSA-2005:831 | View |
111123 | 14595 | CVE-2005-3389 | URL:http://www.redhat.com/support/errata/RHSA-2005-831.html | View |
111124 | 14595 | CVE-2005-3389 | REDHAT:RHSA-2005:838 | View |
111125 | 14595 | CVE-2005-3389 | URL:http://www.redhat.com/support/errata/RHSA-2005-838.html | View |
111126 | 14595 | CVE-2005-3389 | REDHAT:RHSA-2006:0549 | View |
111127 | 14595 | CVE-2005-3389 | URL:http://rhn.redhat.com/errata/RHSA-2006-0549.html | View |
111128 | 14595 | CVE-2005-3389 | SUSE:SUSE-SA:2005:069 | View |
111129 | 14595 | CVE-2005-3389 | URL:http://www.securityfocus.com/archive/1/archive/1/419504/100/0/threaded | View |
111130 | 14595 | CVE-2005-3389 | SUSE:SUSE-SR:2005:026 | View |
111131 | 14595 | CVE-2005-3389 | SUSE:SUSE-SR:2005:027 | View |
111132 | 14595 | CVE-2005-3389 | URL:http://www.novell.com/linux/security/advisories/2005_27_sr.html | View |
111133 | 14595 | CVE-2005-3389 | TURBO:TLSA-2006-38 | View |
111134 | 14595 | CVE-2005-3389 | URL:http://www.turbolinux.com/security/2006/TLSA-2006-38.txt | View |
111135 | 14595 | CVE-2005-3389 | UBUNTU:USN-232-1 | View |
111136 | 14595 | CVE-2005-3389 | URL:https://www.ubuntu.com/usn/usn-232-1/ | View |
111137 | 14595 | CVE-2005-3389 | BID:15249 | View |
111138 | 14595 | CVE-2005-3389 | URL:http://www.securityfocus.com/bid/15249 | View |
111139 | 14595 | CVE-2005-3389 | OVAL:oval:org.mitre.oval:def:11481 | View |
111140 | 14595 | CVE-2005-3389 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11481 | View |
111141 | 14595 | CVE-2005-3389 | VUPEN:ADV-2005-2254 | View |
111142 | 14595 | CVE-2005-3389 | URL:http://www.vupen.com/english/advisories/2005/2254 | View |
111143 | 14595 | CVE-2005-3389 | VUPEN:ADV-2006-4320 | View |
111144 | 14595 | CVE-2005-3389 | URL:http://www.vupen.com/english/advisories/2006/4320 | View |
111145 | 14595 | CVE-2005-3389 | SECTRACK:1015131 | View |
111146 | 14595 | CVE-2005-3389 | URL:http://securitytracker.com/id?1015131 | View |
111147 | 14595 | CVE-2005-3389 | SECUNIA:17371 | View |
111148 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/17371 | View |
111149 | 14595 | CVE-2005-3389 | SECUNIA:18054 | View |
111150 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/18054 | View |
111151 | 14595 | CVE-2005-3389 | SECUNIA:18198 | View |
111152 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/18198 | View |
111153 | 14595 | CVE-2005-3389 | SECUNIA:17559 | View |
111154 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/17559 | View |
111155 | 14595 | CVE-2005-3389 | SECUNIA:17490 | View |
111156 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/17490 | View |
111157 | 14595 | CVE-2005-3389 | SECUNIA:17510 | View |
111158 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/17510 | View |
111159 | 14595 | CVE-2005-3389 | SECUNIA:17531 | View |
111160 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/17531 | View |
111161 | 14595 | CVE-2005-3389 | SECUNIA:17557 | View |
111162 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/17557 | View |
111163 | 14595 | CVE-2005-3389 | SECUNIA:18669 | View |
111164 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/18669 | View |
111165 | 14595 | CVE-2005-3389 | SECUNIA:21252 | View |
111166 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/21252 | View |
111167 | 14595 | CVE-2005-3389 | SECUNIA:22691 | View |
111168 | 14595 | CVE-2005-3389 | URL:http://secunia.com/advisories/22691 | View |
111169 | 14595 | CVE-2005-3389 | SREASON:134 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62457 | JVNDB-2005-000659 | PHP の複数のモジュールに safe_mode および open_basedir ディレクティブによる保護を回避される脆弱性 | ------------ | CVE-2005-3391 | 14595 | 7.5 | http://jvndb.jvn.jp/ja/contents/2005/JVNDB-2005-000659.html | View |