CVE Vulnerabilities

CVE-2006-3011

Published: Jun 26, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a php:// or other scheme in the third argument, which disables safe mode.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp*4.4.3 (including)
PhpPhp1.0 (including)1.0 (including)
PhpPhp2.0 (including)2.0 (including)
PhpPhp2.0b10 (including)2.0b10 (including)
PhpPhp3.0 (including)3.0 (including)
PhpPhp3.0.1 (including)3.0.1 (including)
PhpPhp3.0.2 (including)3.0.2 (including)
PhpPhp3.0.3 (including)3.0.3 (including)
PhpPhp3.0.4 (including)3.0.4 (including)
PhpPhp3.0.5 (including)3.0.5 (including)
PhpPhp3.0.6 (including)3.0.6 (including)
PhpPhp3.0.7 (including)3.0.7 (including)
PhpPhp3.0.8 (including)3.0.8 (including)
PhpPhp3.0.9 (including)3.0.9 (including)
PhpPhp3.0.10 (including)3.0.10 (including)
PhpPhp3.0.11 (including)3.0.11 (including)
PhpPhp3.0.12 (including)3.0.12 (including)
PhpPhp3.0.13 (including)3.0.13 (including)
PhpPhp3.0.14 (including)3.0.14 (including)
PhpPhp3.0.15 (including)3.0.15 (including)
PhpPhp3.0.16 (including)3.0.16 (including)
PhpPhp3.0.17 (including)3.0.17 (including)
PhpPhp3.0.18 (including)3.0.18 (including)
PhpPhp4.0-beta_4_patch1 (including)4.0-beta_4_patch1 (including)
PhpPhp4.0-beta1 (including)4.0-beta1 (including)
PhpPhp4.0-beta2 (including)4.0-beta2 (including)
PhpPhp4.0-beta3 (including)4.0-beta3 (including)
PhpPhp4.0-beta4 (including)4.0-beta4 (including)
PhpPhp4.0.0 (including)4.0.0 (including)
PhpPhp4.0.1 (including)4.0.1 (including)
PhpPhp4.0.2 (including)4.0.2 (including)
PhpPhp4.0.3 (including)4.0.3 (including)
PhpPhp4.0.4 (including)4.0.4 (including)
PhpPhp4.0.5 (including)4.0.5 (including)
PhpPhp4.0.6 (including)4.0.6 (including)
PhpPhp4.0.7 (including)4.0.7 (including)
PhpPhp4.1.0 (including)4.1.0 (including)
PhpPhp4.1.1 (including)4.1.1 (including)
PhpPhp4.1.2 (including)4.1.2 (including)
PhpPhp4.2.0 (including)4.2.0 (including)
PhpPhp4.2.1 (including)4.2.1 (including)
PhpPhp4.2.2 (including)4.2.2 (including)
PhpPhp4.2.3 (including)4.2.3 (including)
PhpPhp4.3.0 (including)4.3.0 (including)
PhpPhp4.3.1 (including)4.3.1 (including)
PhpPhp4.3.2 (including)4.3.2 (including)
PhpPhp4.3.3 (including)4.3.3 (including)
PhpPhp4.3.4 (including)4.3.4 (including)
PhpPhp4.3.5 (including)4.3.5 (including)
PhpPhp4.3.6 (including)4.3.6 (including)
PhpPhp4.3.7 (including)4.3.7 (including)
PhpPhp4.3.8 (including)4.3.8 (including)
PhpPhp4.3.9 (including)4.3.9 (including)
PhpPhp4.3.10 (including)4.3.10 (including)
PhpPhp4.3.11 (including)4.3.11 (including)
PhpPhp4.4.0 (including)4.4.0 (including)
PhpPhp4.4.1 (including)4.4.1 (including)
PhpPhp4.4.2 (including)4.4.2 (including)
Php5Ubuntudapper*

References