CVE-2006-4481 describes a vulnerability in PHP versions prior to 5.1.5, where the file_exists and imap_reopen functions fail to enforce safe_mode and open_basedir settings, enabling local users to bypass these security restrictions. With a CVSS score of 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C), this vulnerability represents a high-severity local attack, allowing for complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.1.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:* | ||
5.1.1CPE matchmatch criteria | cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:* | ||
5.1.2CPE matchmatch criteria | cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:* | ||
5.1.4CPE matchmatch criteria | cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.