CVE-2006-2563: Low severity PHP PHP vulnerability
Published May 29, 2006
·Updated
The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.
Affected Software
2 affected components
PHP PHP=5.1.4
PHP PHP=4.4.2
Event History
May 29, 2006
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2563?
CVE-2006-2563 is considered a medium severity vulnerability due to its potential to allow unauthorized file access.
2
How can I fix CVE-2006-2563?
To fix CVE-2006-2563, it's recommended to upgrade to a version of PHP that is not vulnerable, such as versions later than 5.1.4 and 4.4.2.
3
Which versions of PHP are affected by CVE-2006-2563?
CVE-2006-2563 affects PHP versions 4.4.2 and 5.1.4.
4
What kind of attack does CVE-2006-2563 enable?
CVE-2006-2563 allows attackers to bypass safe mode restrictions and read arbitrary files on the server using crafted file:// requests.
5
Is my server safe if I am not using PHP 4.4.2 or 5.1.4?
If you are using a version of PHP newer than 5.1.4 or 4.4.2, your server is not vulnerable to CVE-2006-2563.