CVE-2005-3389 Affecting php package, versions [4.0.0,5.0.5]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.98% (89th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-PHP-2335395
  • published12 Jan 2022
  • disclosed1 Nov 2005
  • creditUnknown

Introduced: 1 Nov 2005

CVE-2005-3389  (opens in a new tab)

How to fix?

There is no fixed version for php.

Overview

The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.

References

CVSS Scores

version 3.1