Description
The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-232-1 | PHP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T23:10:08.579Z
Reserved: 2005-11-01T00:00:00.000Z
Link: CVE-2005-3389
No data.
Status : Deferred
Published: 2005-11-01T12:47:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-3389
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN