Back

MEDIUM

php: chdir(), ftok() (standard ext) safe_mode bypass safe_mode bypass

Published Jun 20, 2008

Description

Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.

Affected products

Remediation

Red Hat statement

We do not consider these to be security issues. For more details see https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and https://www.php.net/security-note.php

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 20, 2008
Updated Aug 7, 2024
Reserved Jun 10, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jun 18, 2008