PT-2009-5845 · Php · Php

Published

2009-11-23

·

Updated

2024-08-07

·

CVE-2009-3559

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 5.3.x before 5.3.1
Description The issue in PHP does not recognize the safe mode include dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations. This can be demonstrated by a script that attempts to perform a require once on a file in a standard library directory.
Recommendations For PHP versions 5.3.x before 5.3.1, update to version 5.3.1 to resolve the issue.

Fix

Related Identifiers

CVE-2009-3559

Affected Products

Php