Executive Summary

Informations
Name CVE-2006-4481 First vendor Publication 2006-08-31
Vendor Cve Last vendor Modification 2018-10-30

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 7.2 Attack Range Local
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4481

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 4

OpenVAS Exploits

Date Description
2012-06-21 Name : PHP 5.1.x < 5.1.5
File : nvt/nopsec_php_5_1_5.nasl
2008-09-04 Name : FreeBSD Ports: php4, php5
File : nvt/freebsd_php40.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
28009 PHP imap_reopen() Function open_basedir/safe_mode Bypass

PHP contains a flaw that may allow an attacker to bypass security restrictions. The issue is due to the imap_reopen() function not properly sanitizing user-supplied input. By using crafted input, an attacker may be able to bypass the safe_mode and open_basedir security restrictions.
28007 PHP file_exists() Function open_basedir/safe_mode Bypass

PHP contains a flaw that may allow an attacker to bypass security restrictions. The issue is due to the file_exists() function not properly sanitizing user-supplied input. By using crafted input, an attacker may be able to bypass the safe_mode and open_basedir security restrictions.

Nessus® Vulnerability Scanner

Date Description
2011-11-18 Name : The remote web server uses a version of PHP that is affected by multiple vuln...
File : php_5_1_5.nasl - Type : ACT_GATHER_INFO
2007-11-10 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-342-1.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote host is missing a vendor-supplied security patch
File : suse_SA_2006_052.nasl - Type : ACT_GATHER_INFO
2006-12-16 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2006-162.nasl - Type : ACT_GATHER_INFO
2006-09-14 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_ea09c5df436211db81e1000e0c2e438a.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/19582
CONFIRM http://www.php.net/release_5_1_5.php
MANDRIVA http://www.mandriva.com/security/advisories?name=MDKSA-2006:162
SECUNIA http://secunia.com/advisories/21546
http://secunia.com/advisories/21768
http://secunia.com/advisories/21842
http://secunia.com/advisories/22039
SUSE http://www.novell.com/linux/security/advisories/2006_52_php.html
UBUNTU http://www.ubuntu.com/usn/usn-342-1
VUPEN http://www.vupen.com/english/advisories/2006/3318

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
Date Informations
2024-02-02 01:04:50
  • Multiple Updates
2024-02-01 12:02:01
  • Multiple Updates
2023-09-05 12:04:32
  • Multiple Updates
2023-09-05 01:01:52
  • Multiple Updates
2023-09-02 12:04:35
  • Multiple Updates
2023-09-02 01:01:52
  • Multiple Updates
2023-08-12 12:05:25
  • Multiple Updates
2023-08-12 01:01:53
  • Multiple Updates
2023-08-11 12:04:40
  • Multiple Updates
2023-08-11 01:01:55
  • Multiple Updates
2023-08-06 12:04:25
  • Multiple Updates
2023-08-06 01:01:53
  • Multiple Updates
2023-08-04 12:04:30
  • Multiple Updates
2023-08-04 01:01:56
  • Multiple Updates
2023-07-14 12:04:28
  • Multiple Updates
2023-07-14 01:01:54
  • Multiple Updates
2023-03-29 01:04:51
  • Multiple Updates
2023-03-28 12:01:59
  • Multiple Updates
2022-10-11 12:03:58
  • Multiple Updates
2022-10-11 01:01:45
  • Multiple Updates
2021-05-04 12:04:30
  • Multiple Updates
2021-04-22 01:05:10
  • Multiple Updates
2020-05-23 00:18:19
  • Multiple Updates
2019-06-08 12:01:48
  • Multiple Updates
2018-10-31 00:19:46
  • Multiple Updates
2016-06-28 15:56:24
  • Multiple Updates
2016-04-26 15:01:27
  • Multiple Updates
2014-02-17 10:37:08
  • Multiple Updates
2013-05-11 11:08:01
  • Multiple Updates