vendor:
cURL
by:
Unknown
7.5
CVSS
HIGH
Bypassing open_basedir restrictions
22
CWE
Product Name: cURL
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:haxx:curl
Platforms Tested:
Unknown
cURL ‘open_basedir’ Bypass Vulnerability
The cURL module in PHP fails to properly enforce the 'open_basedir' restriction, allowing malicious users to bypass it and access arbitrary files on the server. This can lead to further attacks and unauthorized access to sensitive information.
Mitigation:
Apply the necessary patches or updates provided by the vendor. Additionally, review and strengthen the server's access control measures and permissions to prevent unauthorized access to sensitive files.