CVE-2007-4850

Php - Access Control

Title source: rule

Description

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz · phpremotephp
https://www.exploit-db.com/exploits/31053

References (28)

... and 8 more

Scores

EPSS 0.1393
EPSS Percentile 94.3%

Details

CWE
CWE-264
Status published
Products (2)
php/php 5.2.4
php/php 5.2.5
Published Jan 25, 2008
Tracked Since Feb 18, 2026