PT-2007-4304 · Php · Php

Published

2007-06-04

·

Updated

2022-08-29

·

CVE-2007-3007

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: PHP versions prior to 5.2.3
Description: The issue allows context-dependent attackers to determine the existence of arbitrary files by checking if the readfile function returns a string. This might also involve the realpath function.
Recommendations: For PHP versions prior to 5.2.3, update to version 5.2.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the readfile function and the realpath function until a patch is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2007-3007

Affected Products

Php