Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-7243


PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.


Published

2011-01-18T20:00:10.580

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application php php ≤ 5.3.3 Yes
Application php php 1.0 Yes
Application php php 2.0 Yes
Application php php 2.0b10 Yes
Application php php 3.0 Yes
Application php php 3.0.1 Yes
Application php php 3.0.2 Yes
Application php php 3.0.3 Yes
Application php php 3.0.4 Yes
Application php php 3.0.5 Yes
Application php php 3.0.6 Yes
Application php php 3.0.7 Yes
Application php php 3.0.8 Yes
Application php php 3.0.9 Yes
Application php php 3.0.10 Yes
Application php php 3.0.11 Yes
Application php php 3.0.12 Yes
Application php php 3.0.13 Yes
Application php php 3.0.14 Yes
Application php php 3.0.15 Yes
Application php php 3.0.16 Yes
Application php php 3.0.17 Yes
Application php php 3.0.18 Yes
Application php php 4.0 Yes
Application php php 4.0 Yes
Application php php 4.0 Yes
Application php php 4.0 Yes
Application php php 4.0 Yes
Application php php 4.0 Yes
Application php php 4.0.0 Yes
Application php php 4.0.1 Yes
Application php php 4.0.2 Yes
Application php php 4.0.3 Yes
Application php php 4.0.4 Yes
Application php php 4.0.5 Yes
Application php php 4.0.6 Yes
Application php php 4.0.7 Yes
Application php php 4.1.0 Yes
Application php php 4.1.1 Yes
Application php php 4.1.2 Yes
Application php php 4.2.0 Yes
Application php php 4.2.1 Yes
Application php php 4.2.2 Yes
Application php php 4.2.3 Yes
Application php php 4.3.0 Yes
Application php php 4.3.1 Yes
Application php php 4.3.2 Yes
Application php php 4.3.3 Yes
Application php php 4.3.4 Yes
Application php php 4.3.5 Yes
Application php php 4.3.6 Yes
Application php php 4.3.7 Yes
Application php php 4.3.8 Yes
Application php php 4.3.9 Yes
Application php php 4.3.10 Yes
Application php php 4.3.11 Yes
Application php php 4.4.0 Yes
Application php php 4.4.1 Yes
Application php php 4.4.2 Yes
Application php php 4.4.3 Yes
Application php php 4.4.4 Yes
Application php php 4.4.5 Yes
Application php php 4.4.6 Yes
Application php php 4.4.7 Yes
Application php php 4.4.8 Yes
Application php php 4.4.9 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.1 Yes
Application php php 5.0.2 Yes
Application php php 5.0.3 Yes
Application php php 5.0.4 Yes
Application php php 5.0.5 Yes
Application php php 5.1.0 Yes
Application php php 5.1.1 Yes
Application php php 5.1.2 Yes
Application php php 5.1.3 Yes
Application php php 5.1.4 Yes
Application php php 5.1.5 Yes
Application php php 5.1.6 Yes
Application php php 5.2.0 Yes
Application php php 5.2.1 Yes
Application php php 5.2.2 Yes
Application php php 5.2.3 Yes
Application php php 5.2.4 Yes
Application php php 5.2.4 Yes
Application php php 5.2.5 Yes
Application php php 5.2.6 Yes
Application php php 5.2.7 Yes
Application php php 5.2.8 Yes
Application php php 5.2.9 Yes
Application php php 5.2.10 Yes
Application php php 5.2.11 Yes
Application php php 5.2.12 Yes
Application php php 5.2.13 Yes
Application php php 5.2.14 Yes
Application php php 5.2.15 Yes
Application php php 5.2.16 Yes
Application php php 5.2.17 Yes
Application php php 5.3.0 Yes
Application php php 5.3.1 Yes
Application php php 5.3.2 Yes

References