CVE-2008-7002 describes a vulnerability in PHP 5.2.5 where open_basedir and safe_mode_exec_dir restrictions are not properly enforced for functions like exec, system, and shell_exec. This flaw allows local users to bypass intended access restrictions and execute programs outside allowed directories, potentially using pathnames like "C:" drive notation. With a CVSS score of 7.2 (High), this vulnerability presents a significant risk, as it allows for complete confidentiality, integrity, and availability compromise with low attack complexity. While there is no evidence of active exploitation in the wild, an ExploitDB entry (EDB-32343) confirms the existence of exploit code, though community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.5CPE matchmatch criteria | cpe:2.3:a:php:php:5.2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.