← Back

CVE-2007-1710

nvd nist
Published: Mar 27, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:L/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 3.1 / Impact: 6.4
Source: NVD

Description

The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a "php://../../" sequence.

Affected (3)

Products: Php: Php
1 product
Php
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
Version 4.4.4
Version 5.1.6
Version 5.2.1

Timeline

No history available yet.