CVE
- Id
- 32782
- CVE No.
- CVE-2008-2665
- Status
- Candidate
- Description
- Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has successfully run.
- Phase
- Assigned (20080610)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
354838 | 32782 | CVE-2008-2665 | SREASONRES:20080617 PHP 5.2.6 posix_access() (posix ext) safe_mode bypass | View |
354839 | 32782 | CVE-2008-2665 | URL:http://securityreason.com/achievement_securityalert/54 | View |
354840 | 32782 | CVE-2008-2665 | BUGTRAQ:20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl | View |
354841 | 32782 | CVE-2008-2665 | URL:http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded | View |
354842 | 32782 | CVE-2008-2665 | CONFIRM:http://wiki.rpath.com/Advisories:rPSA-2009-0035 | View |
354843 | 32782 | CVE-2008-2665 | CONFIRM:http://support.apple.com/kb/HT3549 | View |
354844 | 32782 | CVE-2008-2665 | APPLE:APPLE-SA-2009-05-12 | View |
354845 | 32782 | CVE-2008-2665 | URL:http://lists.apple.com/archives/security-announce/2009/May/msg00002.html | View |
354846 | 32782 | CVE-2008-2665 | GENTOO:GLSA-200811-05 | View |
354847 | 32782 | CVE-2008-2665 | URL:http://security.gentoo.org/glsa/glsa-200811-05.xml | View |
354848 | 32782 | CVE-2008-2665 | HP:HPSBUX02431 | View |
354849 | 32782 | CVE-2008-2665 | URL:http://marc.info/?l=bugtraq&m=124654546101607&w=2 | View |
354850 | 32782 | CVE-2008-2665 | HP:SSRT090085 | View |
354851 | 32782 | CVE-2008-2665 | URL:http://marc.info/?l=bugtraq&m=124654546101607&w=2 | View |
354852 | 32782 | CVE-2008-2665 | HP:HPSBUX02465 | View |
354853 | 32782 | CVE-2008-2665 | URL:http://marc.info/?l=bugtraq&m=125631037611762&w=2 | View |
354854 | 32782 | CVE-2008-2665 | HP:SSRT090192 | View |
354855 | 32782 | CVE-2008-2665 | URL:http://marc.info/?l=bugtraq&m=125631037611762&w=2 | View |
354856 | 32782 | CVE-2008-2665 | CERT:TA09-133A | View |
354857 | 32782 | CVE-2008-2665 | URL:http://www.us-cert.gov/cas/techalerts/TA09-133A.html | View |
354858 | 32782 | CVE-2008-2665 | BID:29797 | View |
354859 | 32782 | CVE-2008-2665 | URL:http://www.securityfocus.com/bid/29797 | View |
354860 | 32782 | CVE-2008-2665 | SECTRACK:1020327 | View |
354861 | 32782 | CVE-2008-2665 | URL:http://www.securitytracker.com/id?1020327 | View |
354862 | 32782 | CVE-2008-2665 | SECUNIA:35074 | View |
354863 | 32782 | CVE-2008-2665 | URL:http://secunia.com/advisories/35074 | View |
354864 | 32782 | CVE-2008-2665 | SECUNIA:35650 | View |
354865 | 32782 | CVE-2008-2665 | URL:http://secunia.com/advisories/35650 | View |
354866 | 32782 | CVE-2008-2665 | SECUNIA:32746 | View |
354867 | 32782 | CVE-2008-2665 | URL:http://secunia.com/advisories/32746 | View |
354868 | 32782 | CVE-2008-2665 | SREASON:3941 | View |
354869 | 32782 | CVE-2008-2665 | URL:http://securityreason.com/securityalert/3941 | View |
354870 | 32782 | CVE-2008-2665 | VUPEN:ADV-2009-1297 | View |
354871 | 32782 | CVE-2008-2665 | URL:http://www.vupen.com/english/advisories/2009/1297 | View |
354872 | 32782 | CVE-2008-2665 | XF:php-posixaccess-security-bypass(43196) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
50568 | JVNDB-2008-005878 | yBlog における SQL インジェクションの脆弱性 | yBlog には、SQL インジェクションの脆弱性が存在します。 | CVE-2008-2669 | 32782 | 7.5 | http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-005878.html | View |