fopen_wrappers.c in PHP 4.4.0, and possibly other versions, does not properly restrict access to other directories when the open_basedir directive includes a trailing slash, which allows PHP scripts in one directory to access files in other directories whose names are substrings of the original directory
Published Sep 26, 2005
2.1
LOWCVSS 2.0
EPSS 0.43%
Description
fopen_wrappers.c in PHP 4.4.0, and possibly other versions, does not properly restrict access to other directories when the open_basedir directive includes a trailing slash, which allows PHP scripts in one directory to access files in other directories whose names are substrings of the original directory.
Affected products
Remediation
Red Hat statement
We do not consider these to be security issues: http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00431) | 35.04th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00431) | 34.18th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.68% (0.00682) | 69.93th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00066) | 31.29th | v3 (v2023.03.01) |
| Jun 21, 2024 | 0.08% (0.00078) | 34.09th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.08% (0.00078) | 32.08th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
No CWE recorded.
References (16)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=323585 x_refsource_CONFIRMPatchVendor Advisory
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html vendor-advisoryx_refsource_TRUSTIX
- http://secunia.com/advisories/17229 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17371 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17510 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/17557 third-party-advisoryx_refsource_SECUNIA
- http://www.gentoo.org/security/en/glsa/glsa-200511-08.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:213 vendor-advisoryx_refsource_MANDRIVA
- http://www.php.net/release_4_4_1.php x_refsource_CONFIRM
- http://www.securityfocus.com/bid/14957 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2005/1862 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2005/2254 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2005-3054 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-3054
- https://usn.ubuntu.com/207-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2005-3054
Change history (0)
No recorded changes yet.