VDB
CVE-2010-1130
CVE-2010-1130
PUBLISHED
CVSS 5 MEDIUM
session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).
EPSS 6.31% · 91.1th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
6.31%
91.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| php | php | 5.0.0, 0, 5.0.0 |
| n/a | n/a | * |
Exploit Intelligence
- http://securityreason.com/securityalert/7008 (nist-nvd)
- CIRCL confirmed: CVE-2010-1130 (circl-sighting)
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/session/session.c?r1=293036&r2=294272 (circl)
- ADV-2010-0479 (circl)
- http://www.php.net/releases/5_2_13.php (circl)
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/session/session.c?r1=293036&r2=294272 (circl)
- http://www.php.net/ChangeLog-5.php (circl)
- 38708 (circl)
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/session/session.c?view=log (circl)
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/session/session.c?view=log (circl)
…and 2 more exploits
Timeline
- Feb 11, 2010 PoC Published
- Mar 26, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- http://secunia.com/advisories/38708 advisory
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/session/session.c?r1=293036&r2=294272 url
- ADV-2010-0479 vdb
- http://www.php.net/releases/5_2_13.php url
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/session/session.c?r1=293036&r2=294272 url
- http://www.php.net/ChangeLog-5.php url
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/session/session.c?view=log url
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/session/session.c?view=log url
- 1023661 vdb
- 20100211 PHP 5.2.12/5.3.1 session.save_path safe_mode and open_basedir bypass third-party-advisory
- 7008 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-1130 advisory