Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP ext/standard/file.c tempnam函数权限许可和访问控制漏洞
Vulnerability Description
PHP 5.2.12之前版本和5.3.1之前的5.3.x版本的ext/standard/file.c中的tempnam函数中存在权限许可和访问控制漏洞。攻击者可借助dir和prefix参数绕过安全模式限制并在组可写或全局可写目录中创建文件。
CVSS Information
N/A
Vulnerability Type
N/A