Description
ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2639-1 | php5 security update |
EUVD |
EUVD-2013-1666 | ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T15:13:32.462Z
Reserved: 2013-02-07T00:00:00.000Z
Link: CVE-2013-1635
No data.
Status : Deferred
Published: 2013-03-06T13:10:27.180
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-1635
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD