CVE-2007-5900: Medium severity PHP PHP vulnerability
PHP before 5.2.5 allows local users to bypass protection mechanisms configured through phpadminvalue or phpadminflag in httpd.conf by using iniset to modify arbitrary configuration variables, a different issue than CVE-2006-4625.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5900?
CVE-2007-5900 is classified as a moderate severity vulnerability that allows local users to bypass security mechanisms.
How do I fix CVE-2007-5900?
To fix CVE-2007-5900, you should upgrade PHP to version 5.2.5 or later.
Which versions of PHP are affected by CVE-2007-5900?
CVE-2007-5900 affects all versions of PHP before 5.2.5, specifically including version 5.2.4 and earlier.
What can an attacker do with CVE-2007-5900?
An attacker exploiting CVE-2007-5900 can modify configuration variables, potentially impacting the security of the PHP environment.
Is CVE-2007-5900 related to any other vulnerabilities?
CVE-2007-5900 is a different issue from CVE-2006-4625, although both involve vulnerabilities in PHP configuration.