CVE-2006-1017: Critical severity PHP PHP vulnerability
The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safemode or (2) openbasedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imapopen function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1017?
CVE-2006-1017 has a severity rating of Medium, indicating it poses a moderate risk to affected systems.
How do I fix CVE-2006-1017?
To fix CVE-2006-1017, upgrade to PHP version 4.4.4 or higher, or 5.1.5 or higher.
What types of applications are affected by CVE-2006-1017?
Applications that utilize the c-client library for PHP versions prior to the secure releases are affected by CVE-2006-1017.
Can CVE-2006-1017 lead to remote code execution?
CVE-2006-1017 can potentially be exploited to gain unauthorized access, which may lead to remote code execution.
What library does CVE-2006-1017 affect?
CVE-2006-1017 affects the c-client library used in various versions of PHP.