PT-2007-1480 · Php · Php

Challii

·

Published

2007-05-22

·

Updated

2023-01-19

·

CVE-2006-7204

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 4.4.4
Description The issue concerns the imap body function, which does not implement safemode or open basedir checks. This allows local users to read arbitrary files or list arbitrary directory contents.
Recommendations For versions prior to 4.4.4, update to version 4.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the imap body function until a patch is available.

Fix

Related Identifiers

CVE-2006-7204

Affected Products

Php