PT-2009-5845 · Php · Php

CVE-2009-3559

·

Publicado

2009-11-23

·

Atualizado

2024-08-07

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 5.3.x before 5.3.1
Description The issue in PHP does not recognize the safe mode include dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations. This can be demonstrated by a script that attempts to perform a require once on a file in a standard library directory.
Recommendations For PHP versions 5.3.x before 5.3.1, update to version 5.3.1 to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-3559

Produtos afetados

Php