PHP Permissions Privileges and Access Controls Vulnerability - CVE-2010-1130 - Vulnerability Database

PHP Permissions Privileges and Access Controls Vulnerability - CVE-2010-1130

Medium
Reference: CVE-2010-1130
Title: PHP Permissions Privileges and Access Controls Vulnerability
Overview:

session.c in the session extension in PHP before 5.2.13 and 5.3.1 does not properly interpret (semicolon) characters in the argument to the session_save_path function which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple characters in conjunction with a .. (dot dot).