PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625
Published Nov 20, 2007
6.9
MEDIUMCVSS 2.0
EPSS 0.34%
Description
PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.
Affected products
Remediation
Red Hat statement
The PHP interpreter does not offer a reliable "sandboxed" security layer (as found in, say, a JVM) in which untrusted scripts can be run; any script run by the PHP interpreter must be trusted with the privileges of the interpreter itself. We therefore do not classify this issue as security-sensitive since no trust boundary is crossed.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.34% (0.00340) | 25.13th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.34% (0.00340) | 25.64th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.05% (0.00052) | 13.31th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 17.90th | v3 (v2023.03.01) |
| May 1, 2024 | 0.04% (0.00045) | 14.49th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00045) | 12.44th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (13)
- http://bugs.php.net/bug.php?id=41561 x_refsource_CONFIRM
- http://secunia.com/advisories/27648 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/27659 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30040 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1018934 vdb-entryx_refsource_SECTRACK
- http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0242 x_refsource_CONFIRM
- http://www.php.net/ChangeLog-5.php#5.2.5 x_refsource_CONFIRM
- http://www.php.net/releases/5_2_5.php x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/491693/100/0/threaded vendor-advisoryx_refsource_HP
- https://access.redhat.com/security/cve/CVE-2007-5900 Vendor Advisory
- https://issues.rpath.com/browse/RPL-1943 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-5900
- https://www.cve.org/CVERecord?id=CVE-2007-5900
| Link | Providers | Tags |
|---|---|---|
| http://bugs.php.net/bug.php?id=41561 | x_refsource_CONFIRM | |
| http://secunia.com/advisories/27648 | third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory | |
| http://secunia.com/advisories/27659 | third-party-advisoryx_refsource_SECUNIA | |
| http://secunia.com/advisories/30040 | third-party-advisoryx_refsource_SECUNIA | |
| http://securitytracker.com/id?1018934 | vdb-entryx_refsource_SECTRACK | |
| http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0242 | x_refsource_CONFIRM | |
| http://www.php.net/ChangeLog-5.php#5.2.5 | x_refsource_CONFIRM | |
| http://www.php.net/releases/5_2_5.php | x_refsource_CONFIRM | |
| http://www.securityfocus.com/archive/1/491693/100/0/threaded | vendor-advisoryx_refsource_HP | |
| https://access.redhat.com/security/cve/CVE-2007-5900 | Vendor Advisory | |
| https://issues.rpath.com/browse/RPL-1943 | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2007-5900 | ||
| https://www.cve.org/CVERecord?id=CVE-2007-5900 |
Change history (0)
No recorded changes yet.