Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-4850

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.139
EPSS Ranking 94.1%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2007-4850
  • Php » Php » Version: 5.2.4
    cpe:2.3:a:php:php:5.2.4
  • Php » Php » Version: 5.2.5
    cpe:2.3:a:php:php:5.2.5


Contact Us

Shodan ® - All rights reserved