Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-4625

19
FAUCET Score

CVE-2006-4625 describes a local bypass vulnerability in PHP versions 4.x up to 4.4.4 and 5.x up to 5.1.6, allowing attackers to circumvent Apache httpd.conf restrictions like safe_mode and open_basedir using the ini_restore function. With a CVSS score of 3.6 (low severity), this vulnerability requires local access and has low attack complexity, potentially leading to partial confidentiality and integrity compromise. While not actively exploited in the wild and not on CISA's KEV catalog, an ExploitDB entry exists, but there is no evidence of widespread community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
4.0CPE matchmatch criteria
cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*
4.0.2CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

3.6LOW

AV:L/AC:L/Au:N/C:P/I:P/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.91%
Probability of exploitation in next 30 days
EPSS Percentile
56.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-28504 · Sep 9, 2006
This CVE's current EPSS score of 0.0091 is in the 89th percentile among its peer group of 2,096 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2006-4625Low

CVE-2006-4625 PHP safe mode bypass

Sep 9, 2006

References

h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
lists.suse.com / archive/suse-security-announce/2006-Oct/0002.html
secunia.com / advisories/22282
secunia.com / advisories/22331
secunia.com / advisories/22338
secunia.com / advisories/22424
secunia.com / advisories/25423
secunia.com / advisories/25850
securityreason.com / achievement_securityalert/42
ExploitPatch
securityreason.com / securityalert/1519
exchange.xforce.ibmcloud.com / vulnerabilities/28853
mandriva.com / security/advisories
securityfocus.com / archive/1/445712/100/0/threaded
securityfocus.com / archive/1/445882/100/0/threaded
securityfocus.com / archive/1/448953/100/0/threaded
securityfocus.com / bid/19933
Exploit
turbolinux.com / security/2006/TLSA-2006-38.txt
ubuntu.com / usn/usn-362-1
vupen.com / english/advisories/2007/1991
vupen.com / english/advisories/2007/2374