peter bassill · operator
$ cve CVE-2006-1494 JSON

CVE-2006-1494 EXPLOIT

2.6
LOW · CVSS 2.0 · EPSS 6.4% (pctl 94)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

Scoring

CVSS2.6 (LOW, v2.0)
VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS6.39% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2006-04-10
Last modified2026-06-16

Affected (1)

VendorProduct
phpphp

Public exploits

SourceTitleDate
exploit-dbPHP 4.x - 'tempnam() open_basedir' Restriction Bypass2006-04-10

References

→ the Explorer  ·  watch your stack  ·  NVD