CVE-2008-5625
published 2008-12-17CVE-2008-5625: PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows…
PriorityP346high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
7.31%
93.6th percentile
PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| php | php | <= 5.2.6 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x9qw-wpgc-3724: PHP 5 before 5
ghsa_unreviewed·2022-05-14
CVE-2008-5625 [HIGH] GHSA-x9qw-wpgc-3724: PHP 5 before 5
PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2009-02-12·CVSS 6.9
CVE-2008-3659 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: PHP vulnerabilities
It was discovered that PHP did not properly enforce php_admin_value and
php_admin_flag restrictions in the Apache configuration file. A local attacker
could create a specially crafted PHP script that would bypass intended security
restrictions. This issue only applied to Ubuntu 6.06 LTS, 7.10, and 8.04 LTS.
(CVE-2007-5900)
It was discovered that PHP did not correctly handle certain malformed font
files. If a PHP application were tricked into processing a specially crafted
font file, an attacker may be able to cause a denial of service and possibly
execute arbitrary code with application privileges. (CVE-2008-3658)
It was discovered that PHP did not properly check the delimiter argument to the
explode function. If a script passed u
Red Hat
php: incorrect php_value order for Apache configuration
vendor_redhat·2008-12-04·CVSS 7.5
CVE-2008-5625 [HIGH] php: incorrect php_value order for Apache configuration
php: incorrect php_value order for Apache configuration
PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.
Statement: We do not consider this to be a security issue. For more details see https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and https://www.php.net/security-note.php
No detection rules found.
http://archives.neohapsis.com/archives/bugtraq/2008-11/0152.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://osvdb.org/52205http://secunia.com/advisories/35650http://securityreason.com/achievement_securityalert/57http://wiki.rpath.com/Advisories:rPSA-2009-0035http://www.mandriva.com/security/advisories?name=MDVSA-2009:045http://www.php.net/ChangeLog-5.php#5.2.7http://www.securityfocus.com/archive/1/501376/100/0/threadedhttp://www.securityfocus.com/bid/32383https://exchange.xforce.ibmcloud.com/vulnerabilities/47314https://www.exploit-db.com/exploits/7171http://archives.neohapsis.com/archives/bugtraq/2008-11/0152.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://osvdb.org/52205http://secunia.com/advisories/35650http://securityreason.com/achievement_securityalert/57http://wiki.rpath.com/Advisories:rPSA-2009-0035http://www.mandriva.com/security/advisories?name=MDVSA-2009:045http://www.php.net/ChangeLog-5.php#5.2.7http://www.securityfocus.com/archive/1/501376/100/0/threadedhttp://www.securityfocus.com/bid/32383https://exchange.xforce.ibmcloud.com/vulnerabilities/47314https://www.exploit-db.com/exploits/7171
2008-12-17
Published