PT-2006-5410 · Php+1 · Php+1

Maksymilian Arciemowicz

·

Published

2006-09-12

·

Updated

2018-10-30

·

CVE-2006-4625

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 4.x up to 4.4.4 PHP versions 5 up to 5.1.6
Description The issue allows local users to bypass certain Apache HTTP Server httpd.conf options. This is achieved via the ini restore function, which resets the values to their php.ini (Master Value) defaults, affecting options such as safe mode and open basedir.
Recommendations For PHP versions 4.x up to 4.4.4, consider updating to a version where this issue is resolved. For PHP versions 5 up to 5.1.6, consider updating to a version where this issue is resolved. As a temporary workaround, consider restricting the use of the ini restore function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4625

Affected Products

Apache Http Server
Php