Unrated severityNVD Advisory· Published Mar 27, 2007· Updated Apr 23, 2026
CVE-2007-1710
CVE-2007-1710
Description
The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a "php://../../" sequence.
Affected products
4- Range: =4.4.4 || =5.1.6 || =5.2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvd
- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvd
- secunia.com/advisories/25423nvd
- secunia.com/advisories/25850nvd
- www.vupen.com/english/advisories/2007/1991nvd
- www.vupen.com/english/advisories/2007/2374nvd
- www.exploit-db.com/exploits/3573nvd
News mentions
0No linked articles in our index yet.