CVE-2006-7204 Information

Share on:

Description

The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks which allows local users to read arbitrary files or list arbitrary directory contents.

Reference

http://bugs.php.net/bug.php?id=37265 http://secunia.com/advisories/21546 http://us2.php.net/ChangeLog-4.php4.4.4 http://www.osvdb.org/28005