CVE
- Id
- 20729
- CVE No.
- CVE-2006-4625
- Status
- Candidate
- Description
- PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.
- Phase
- Assigned (20060907)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 195855 | 20729 | CVE-2006-4625 | SREASONRES:20060909 PHP 5.1.6 / 4.4.4 Critical php_admin* bypass by ini_restore() | View |
| 195856 | 20729 | CVE-2006-4625 | URL:http://securityreason.com/achievement_securityalert/42 | View |
| 195857 | 20729 | CVE-2006-4625 | BUGTRAQ:20060909 Re: PHP 5.1.6 / 4.4.4 Critical php_admin* bypass by ini_restore() | View |
| 195858 | 20729 | CVE-2006-4625 | URL:http://www.securityfocus.com/archive/1/archive/1/445712/100/0/threaded | View |
| 195859 | 20729 | CVE-2006-4625 | BUGTRAQ:20060913 Re: PHP 5.1.6 / 4.4.4 Critical php_admin* bypass by ini_restore() | View |
| 195860 | 20729 | CVE-2006-4625 | URL:http://www.securityfocus.com/archive/1/archive/1/445882/100/0/threaded | View |
| 195861 | 20729 | CVE-2006-4625 | HP:HPSBMA02215 | View |
| 195862 | 20729 | CVE-2006-4625 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506 | View |
| 195863 | 20729 | CVE-2006-4625 | HP:SSRT071423 | View |
| 195864 | 20729 | CVE-2006-4625 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506 | View |
| 195865 | 20729 | CVE-2006-4625 | HP:HPSBTU02232 | View |
| 195866 | 20729 | CVE-2006-4625 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137 | View |
| 195867 | 20729 | CVE-2006-4625 | HP:SSRT071429 | View |
| 195868 | 20729 | CVE-2006-4625 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137 | View |
| 195869 | 20729 | CVE-2006-4625 | MANDRIVA:MDKSA-2006:185 | View |
| 195870 | 20729 | CVE-2006-4625 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:185 | View |
| 195871 | 20729 | CVE-2006-4625 | OPENPKG:OpenPKG-SA-2006.023 | View |
| 195872 | 20729 | CVE-2006-4625 | URL:http://www.securityfocus.com/archive/1/archive/1/448953/100/0/threaded | View |
| 195873 | 20729 | CVE-2006-4625 | SUSE:SUSE-SA:2006:059 | View |
| 195874 | 20729 | CVE-2006-4625 | URL:http://lists.suse.com/archive/suse-security-announce/2006-Oct/0002.html | View |
| 195875 | 20729 | CVE-2006-4625 | TURBO:TLSA-2006-38 | View |
| 195876 | 20729 | CVE-2006-4625 | URL:http://www.turbolinux.com/security/2006/TLSA-2006-38.txt | View |
| 195877 | 20729 | CVE-2006-4625 | UBUNTU:USN-362-1 | View |
| 195878 | 20729 | CVE-2006-4625 | URL:http://www.ubuntu.com/usn/usn-362-1 | View |
| 195879 | 20729 | CVE-2006-4625 | BID:19933 | View |
| 195880 | 20729 | CVE-2006-4625 | URL:http://www.securityfocus.com/bid/19933 | View |
| 195881 | 20729 | CVE-2006-4625 | VUPEN:ADV-2007-1991 | View |
| 195882 | 20729 | CVE-2006-4625 | URL:http://www.vupen.com/english/advisories/2007/1991 | View |
| 195883 | 20729 | CVE-2006-4625 | VUPEN:ADV-2007-2374 | View |
| 195884 | 20729 | CVE-2006-4625 | URL:http://www.vupen.com/english/advisories/2007/2374 | View |
| 195885 | 20729 | CVE-2006-4625 | SECUNIA:22282 | View |
| 195886 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/22282 | View |
| 195887 | 20729 | CVE-2006-4625 | SECUNIA:22338 | View |
| 195888 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/22338 | View |
| 195889 | 20729 | CVE-2006-4625 | SECUNIA:22424 | View |
| 195890 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/22424 | View |
| 195891 | 20729 | CVE-2006-4625 | SECUNIA:22331 | View |
| 195892 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/22331 | View |
| 195893 | 20729 | CVE-2006-4625 | SECUNIA:25423 | View |
| 195894 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/25423 | View |
| 195895 | 20729 | CVE-2006-4625 | SECUNIA:25850 | View |
| 195896 | 20729 | CVE-2006-4625 | URL:http://secunia.com/advisories/25850 | View |
| 195897 | 20729 | CVE-2006-4625 | SREASON:1519 | View |
| 195898 | 20729 | CVE-2006-4625 | URL:http://securityreason.com/securityalert/1519 | View |
| 195899 | 20729 | CVE-2006-4625 | XF:php-inirestore-security-bypass(28853) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 59802 | JVNDB-2006-002068 | System Information ActiveX control におけるサービス運用妨害 (DoS) の脆弱性 | System Information ActiveX コントロール (msinfo.dll) には、Microsoft Internet Explorer を経由してアクセスされる際、サービス運用妨害 (クラッシュ) 状態となる脆弱性が存在します。 | CVE-2006-4627 | 20729 | 5 | http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-002068.html | View |