Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-1710

The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a "php://../../" sequence.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.0%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2007-1710
  • Php » Php » Version: 4.4.4
    cpe:2.3:a:php:php:4.4.4
  • Php » Php » Version: 5.1.6
    cpe:2.3:a:php:php:5.1.6
  • Php » Php » Version: 5.2.1
    cpe:2.3:a:php:php:5.2.1


Contact Us

Shodan ® - All rights reserved