VDB

CVE-2005-3389

CVE-2005-3389 PUBLISHED

Reported by mitre · Published November 1, 2005

The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a, n/a

Timeline

  • Nov 1, 2005 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Dec 17, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 24, 2023 EPSS Score
  • Jul 15, 2023 EPSS Score
  • Oct 28, 2023 EPSS Score
  • Dec 20, 2023 EPSS Score

References

…and 13 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›