CVE Vulnerabilities

CVE-2006-7204

Published: May 22, 2007 | Modified: Jan 19, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users to read arbitrary files or list arbitrary directory contents.

Affected Software

Name Vendor Start Version End Version
Php Php 4.4.0 (including) 4.4.4 (excluding)
Php Php 5.1.0 (including) 5.1.5 (excluding)

References