Looking for the vulnerability index of Invicti's legacy products?
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1635) - Vulnerability Database

PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1635)

Description

ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.

References

Related Vulnerabilities