CVE-2009-4018 describes a safe_mode bypass vulnerability in the proc_open function of PHP versions before 5.2.11 and 5.3.x before 5.3.1. This flaw allows attackers to execute programs with an arbitrary environment by manipulating the env parameter, bypassing safe_mode_allowed_env_vars and safe_mode_protected_env_vars directives. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing for full confidentiality, integrity, and availability impact with low attack complexity and no authentication required. While not listed on the KEV catalog or Hot List, exploit code is publicly available via ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2.10CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:* | ||
2.0b10CPE matchmatch criteria | cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.