Security Advisory

CVE-2008-2666

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-06-20 01:00:00
Last updated 2024-08-07 09:05:30
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.