CVE
- Id
- 32783
- CVE No.
- CVE-2008-2666
- Status
- Candidate
- Description
- Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.
- Phase
- Assigned (20080610)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
354873 | 32783 | CVE-2008-2666 | SREASONRES:20080617 PHP 5.2.6 chdir(),ftok() (standard ext) safe_mode bypass | View |
354874 | 32783 | CVE-2008-2666 | URL:http://securityreason.com/achievement_securityalert/55 | View |
354875 | 32783 | CVE-2008-2666 | BUGTRAQ:20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl | View |
354876 | 32783 | CVE-2008-2666 | URL:http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded | View |
354877 | 32783 | CVE-2008-2666 | CONFIRM:http://wiki.rpath.com/Advisories:rPSA-2009-0035 | View |
354878 | 32783 | CVE-2008-2666 | CONFIRM:http://support.apple.com/kb/HT3549 | View |
354879 | 32783 | CVE-2008-2666 | APPLE:APPLE-SA-2009-05-12 | View |
354880 | 32783 | CVE-2008-2666 | URL:http://lists.apple.com/archives/security-announce/2009/May/msg00002.html | View |
354881 | 32783 | CVE-2008-2666 | GENTOO:GLSA-200811-05 | View |
354882 | 32783 | CVE-2008-2666 | URL:http://security.gentoo.org/glsa/glsa-200811-05.xml | View |
354883 | 32783 | CVE-2008-2666 | HP:HPSBUX02431 | View |
354884 | 32783 | CVE-2008-2666 | URL:http://marc.info/?l=bugtraq&m=124654546101607&w=2 | View |
354885 | 32783 | CVE-2008-2666 | HP:SSRT090085 | View |
354886 | 32783 | CVE-2008-2666 | URL:http://marc.info/?l=bugtraq&m=124654546101607&w=2 | View |
354887 | 32783 | CVE-2008-2666 | HP:HPSBUX02465 | View |
354888 | 32783 | CVE-2008-2666 | URL:http://marc.info/?l=bugtraq&m=125631037611762&w=2 | View |
354889 | 32783 | CVE-2008-2666 | HP:SSRT090192 | View |
354890 | 32783 | CVE-2008-2666 | URL:http://marc.info/?l=bugtraq&m=125631037611762&w=2 | View |
354891 | 32783 | CVE-2008-2666 | CERT:TA09-133A | View |
354892 | 32783 | CVE-2008-2666 | URL:http://www.us-cert.gov/cas/techalerts/TA09-133A.html | View |
354893 | 32783 | CVE-2008-2666 | BID:29796 | View |
354894 | 32783 | CVE-2008-2666 | URL:http://www.securityfocus.com/bid/29796 | View |
354895 | 32783 | CVE-2008-2666 | SECTRACK:1020328 | View |
354896 | 32783 | CVE-2008-2666 | URL:http://www.securitytracker.com/id?1020328 | View |
354897 | 32783 | CVE-2008-2666 | SECUNIA:35074 | View |
354898 | 32783 | CVE-2008-2666 | URL:http://secunia.com/advisories/35074 | View |
354899 | 32783 | CVE-2008-2666 | SECUNIA:35650 | View |
354900 | 32783 | CVE-2008-2666 | URL:http://secunia.com/advisories/35650 | View |
354901 | 32783 | CVE-2008-2666 | SECUNIA:32746 | View |
354902 | 32783 | CVE-2008-2666 | URL:http://secunia.com/advisories/32746 | View |
354903 | 32783 | CVE-2008-2666 | SREASON:3942 | View |
354904 | 32783 | CVE-2008-2666 | URL:http://securityreason.com/securityalert/3942 | View |
354905 | 32783 | CVE-2008-2666 | VUPEN:ADV-2009-1297 | View |
354906 | 32783 | CVE-2008-2666 | URL:http://www.vupen.com/english/advisories/2009/1297 | View |
354907 | 32783 | CVE-2008-2666 | XF:php-chdir-ftoc-security-bypass(43198) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
49223 | JVNDB-2008-004533 | Insanely Simple Blog の index.php における SQL インジェクションの脆弱性 | Insanely Simple Blog の index.php には、SQL インジェクションの脆弱性が存在します。 | CVE-2008-2670 | 32783 | 7.5 | http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-004533.html | View |