CVE-2008-7002
Last modified
CVE-2008-7002 is a vulnerability of currently unknown severity. PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | 5.2.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-7002?
How severe is CVE-2008-7002?
How do I fix CVE-2008-7002?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-6996Google Chrome BETA (0.2.149.27) does not prompt the user bef…
- CVE-2008-6997Google Chrome 0.2.149.27 allows user-assisted remote attacke…
- CVE-2008-6998Stack-based buffer overflow in chrome/common/gfx/url_elider.…
- CVE-2008-6999phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows…
- CVE-2008-7000PHP remote file inclusion vulnerability in index.php in PHPA…
- CVE-2008-7001Unrestricted file upload vulnerability in the file manager i…
- CVE-2008-7003Multiple SQL injection vulnerabilities in login.php in The R…
- CVE-2008-7004Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 ha…
- CVE-2008-7005include/modules/top/1-random_quote.php in Minb Is Not a Blog…
- CVE-2008-7006Free PHP VX Guestbook 1.06 allows remote attackers to bypass…
- CVE-2008-7007Free PHP VX Guestbook 1.06 allows remote attackers to bypass…
- CVE-2008-7008HyperStop Web Host Directory 1.2 allows remote attackers to …
Are you affected by CVE-2008-7002?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
