ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2013-03-06T11:00:00
Updated: 2014-01-24T17:57:01
Reserved: 2013-02-07T00:00:00
Link: CVE-2013-1635
JSON object: View
NVD Information
Status : Modified
Published: 2013-03-06T13:10:27.180
Modified: 2023-11-07T02:14:46.940
Link: CVE-2013-1635
JSON object: View
Redhat Information
No data.
CWE