CVE
- Id
- 20729
- CVE No.
- CVE-2006-4625
- Status
- Candidate
- Description
- PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
- Phase
- Assigned (20060907)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
195855 | 20729 | CVE-2006-4625 | SREASONRES:20060909 PHP 5.1.6 / 4.4.4 Critical php_admin* bypass by ini_restore() | View |
195856 | 20729 | CVE-2006-4625 | URL:http://securityreason.com/achievement_securityalert/42 | View |
195857 | 20729 | CVE-2006-4625 | BUGTRAQ:20060909 Re: PHP 5.1.6 / 4.4.4 Critical php_admin* bypass by ini_restore() | View |
195858 | 20729 | CVE-2006-4625 | URL:http://www.securityfocus.com/archive/1/archive/1/445712/100/0/threaded | View |
195859 | 20729 | CVE-2006-4625 | BUGTRAQ:20060913 Re: PHP 5.1.6 / 4.4.4 Critical php_admin* bypass by ini_restore() | View |
195860 | 20729 | CVE-2006-4625 | URL:http://www.securityfocus.com/archive/1/archive/1/445882/100/0/threaded | View |
195861 | 20729 | CVE-2006-4625 | HP:HPSBMA02215 | View |
195862 | 20729 | CVE-2006-4625 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506 | View |
195863 | 20729 | CVE-2006-4625 | HP:SSRT071423 | View |
195864 | 20729 | CVE-2006-4625 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506 | View |
195865 | 20729 | CVE-2006-4625 | HP:HPSBTU02232 | View |
195866 | 20729 | CVE-2006-4625 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137 | View |
195867 | 20729 | CVE-2006-4625 | HP:SSRT071429 | View |
195868 | 20729 | CVE-2006-4625 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137 | View |
195869 | 20729 | CVE-2006-4625 | MANDRIVA:MDKSA-2006:185 | View |
195870 | 20729 | CVE-2006-4625 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:185 | View |
195871 | 20729 | CVE-2006-4625 | OPENPKG:OpenPKG-SA-2006.023 | View |
195872 | 20729 | CVE-2006-4625 | URL:http://www.securityfocus.com/archive/1/archive/1/448953/100/0/threaded | View |
195873 | 20729 | CVE-2006-4625 | SUSE:SUSE-SA:2006:059 | View |
195874 | 20729 | CVE-2006-4625 | URL:http://lists.suse.com/archive/suse-security-announce/2006-Oct/0002.html | View |
195875 | 20729 | CVE-2006-4625 | TURBO:TLSA-2006-38 | View |
195876 | 20729 | CVE-2006-4625 | URL:http://www.turbolinux.com/security/2006/TLSA-2006-38.txt | View |
195877 | 20729 | CVE-2006-4625 | UBUNTU:USN-362-1 | View |
195878 | 20729 | CVE-2006-4625 | URL:http://www.ubuntu.com/usn/usn-362-1 | View |
195879 | 20729 | CVE-2006-4625 | BID:19933 | View |
195880 | 20729 | CVE-2006-4625 | URL:http://www.securityfocus.com/bid/19933 | View |
195881 | 20729 | CVE-2006-4625 | VUPEN:ADV-2007-1991 | View |
195882 | 20729 | CVE-2006-4625 | URL:http://www.vupen.com/english/advisories/2007/1991 | View |
195883 | 20729 | CVE-2006-4625 | VUPEN:ADV-2007-2374 | View |
195884 | 20729 | CVE-2006-4625 | URL:http://www.vupen.com/english/advisories/2007/2374 | View |
195885 | 20729 | CVE-2006-4625 | SECUNIA:22282 | View |
195886 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/22282 | View |
195887 | 20729 | CVE-2006-4625 | SECUNIA:22338 | View |
195888 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/22338 | View |
195889 | 20729 | CVE-2006-4625 | SECUNIA:22424 | View |
195890 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/22424 | View |
195891 | 20729 | CVE-2006-4625 | SECUNIA:22331 | View |
195892 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/22331 | View |
195893 | 20729 | CVE-2006-4625 | SECUNIA:25423 | View |
195894 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/25423 | View |
195895 | 20729 | CVE-2006-4625 | SECUNIA:25850 | View |
195896 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/25850 | View |
195897 | 20729 | CVE-2006-4625 | SREASON:1519 | View |
195898 | 20729 | CVE-2006-4625 | URL:http://securityreason.com/securityalert/1519 | View |
195899 | 20729 | CVE-2006-4625 | XF:php-inirestore-security-bypass(28853) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
59802 | JVNDB-2006-002068 | System Information ActiveX control におけるサービス運用妨害 (DoS) の脆弱性 | System Information ActiveX コントロール (msinfo.dll) には、Microsoft Internet Explorer を経由してアクセスされる際、サービス運用妨害 (クラッシュ) 状態となる脆弱性が存在します。 | CVE-2006-4627 | 20729 | 5 | http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-002068.html | View |