CVE Vulnerabilities

CVE-2006-7204

Published: May 22, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users to read arbitrary files or list arbitrary directory contents.

Affected Software

Name Vendor Start Version End Version
Php Php 4.4.0 (including) 4.4.4 (excluding)
Php Php 5.1.0 (including) 5.1.5 (excluding)

References