Back

MEDIUM

security flaw

Published Nov 1, 2005

Description

The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 1, 2005
Updated Aug 7, 2024
Reserved Nov 1, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 31, 2005
ENISA EUVD
Assigner mitre
Published Nov 1, 2005
Updated Aug 7, 2024
Exploited since n/a
EUVD-2005-3388