PHP Other Vulnerability - CVE-2005-3389 - Vulnerability Database

PHP Other Vulnerability - CVE-2005-3389

Medium
Reference: CVE-2005-3389
Title: PHP Other Vulnerability
Overview:

The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 when called with only one parameter allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.