Back
CVE-2005-3392
Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
Published: Nov 1, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (54)
| Vendor | Product | Version |
|---|---|---|
| php | php | 3.0 |
| php | php | 3.0.1 |
| php | php | 3.0.2 |
| php | php | 3.0.3 |
| php | php | 3.0.4 |
| php | php | 3.0.5 |
| php | php | 3.0.6 |
| php | php | 3.0.7 |
| php | php | 3.0.8 |
| php | php | 3.0.9 |
| php | php | 3.0.10 |
| php | php | 3.0.11 |
| php | php | 3.0.12 |
| php | php | 3.0.13 |
| php | php | 3.0.14 |
| php | php | 3.0.15 |
| php | php | 3.0.16 |
| php | php | 3.0.17 |
| php | php | 3.0.18 |
| php | php | 4.0.0 |
…and 34 more
GitHub Security Advisory GHSA-6x5p-g335-gjh8
Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2,...
References (44)
- http://docs.info.apple.com/article.html?artnum=303382
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522
- http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html
- http://secunia.com/advisories/17371 Patch, Vendor Advisory
- http://secunia.com/advisories/17510
- http://secunia.com/advisories/18054
- http://secunia.com/advisories/18198
- http://secunia.com/advisories/19064
- http://secunia.com/advisories/22691
- http://securityreason.com/securityalert/525
- http://www.gentoo.org/security/en/glsa/glsa-200511-08.xml
- http://www.osvdb.org/20897
- http://www.php.net/release_4_4_1.php Patch
- http://www.securityfocus.com/archive/1/419504/100/0/threaded
- http://www.securityfocus.com/bid/15413
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
6.90%
Top 6% most likely to be exploited
Threat Score
32.1 / 100
Data Sources
NVD
EPSS
GitHub