CVE-2013-1635
Description
ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.
Risk Information
Base Score
8.2
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS Score
Exploitation Probability
3.709
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities are fixed in OS X Mountain Lion Update v10.8.5 (Combo) | Mac |
| Multiple vulnerabilities are fixed in OS X Mountain Lion Update v10.8.5 | Mac |
| Apcu-panel update (ELSA-2023-2903) apcu-panel-5.1.18-1.module+el8.3.0+7685+72d70b58.noarch.rpm | Linux |
| Libzip update (ELSA-2023-2903) libzip-1.6.1-1.module+el8.3.0+7685+72d70b58.x86_64.rpm | Linux |
| Libzip-devel update (ELSA-2023-2903) libzip-devel-1.6.1-1.module+el8.3.0+7685+72d70b58.x86_64.rpm | Linux |
| Libzip-tools update (ELSA-2023-2903) libzip-tools-1.6.1-1.module+el8.3.0+7685+72d70b58.x86_64.rpm | Linux |
| Php update (ELSA-2023-2903) php-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-bcmath update (ELSA-2023-2903) php-bcmath-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-cli update (ELSA-2023-2903) php-cli-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-common update (ELSA-2023-2903) php-common-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-dba update (ELSA-2023-2903) php-dba-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-dbg update (ELSA-2023-2903) php-dbg-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-devel update (ELSA-2023-2903) php-devel-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-embedded update (ELSA-2023-2903) php-embedded-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-enchant update (ELSA-2023-2903) php-enchant-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-ffi update (ELSA-2023-2903) php-ffi-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-fpm update (ELSA-2023-2903) php-fpm-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-gd update (ELSA-2023-2903) php-gd-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-gmp update (ELSA-2023-2903) php-gmp-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-intl update (ELSA-2023-2903) php-intl-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-json update (ELSA-2023-2903) php-json-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-ldap update (ELSA-2023-2903) php-ldap-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-mbstring update (ELSA-2023-2903) php-mbstring-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-mysqlnd update (ELSA-2023-2903) php-mysqlnd-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-odbc update (ELSA-2023-2903) php-odbc-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-opcache update (ELSA-2023-2903) php-opcache-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-pdo update (ELSA-2023-2903) php-pdo-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-pear update (ELSA-2023-2903) php-pear-1.10.13-1.module+el8.7.0+20800+8e29b882.noarch.rpm | Linux |
| Php-pecl-apcu update (ELSA-2023-2903) php-pecl-apcu-5.1.18-1.module+el8.3.0+7685+72d70b58.x86_64.rpm | Linux |
| Php-pecl-apcu-devel update (ELSA-2023-2903) php-pecl-apcu-devel-5.1.18-1.module+el8.3.0+7685+72d70b58.x86_64.rpm | Linux |
| Php-pecl-rrd update (ELSA-2023-2903) php-pecl-rrd-2.0.1-1.module+el8.3.0+7685+72d70b58.x86_64.rpm | Linux |
| Php-pecl-xdebug update (ELSA-2023-2903) php-pecl-xdebug-2.9.5-1.module+el8.3.0+7685+72d70b58.x86_64.rpm | Linux |
| Php-pecl-zip update (ELSA-2023-2903) php-pecl-zip-1.18.2-1.module+el8.3.0+7685+72d70b58.x86_64.rpm | Linux |
| Php-pgsql update (ELSA-2023-2903) php-pgsql-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-process update (ELSA-2023-2903) php-process-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-snmp update (ELSA-2023-2903) php-snmp-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-soap update (ELSA-2023-2903) php-soap-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-xml update (ELSA-2023-2903) php-xml-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| Php-xmlrpc update (ELSA-2023-2903) php-xmlrpc-7.4.33-1.module+el8.8.0+20974+ef7eddfa.x86_64.rpm | Linux |
| CVE-2013-1635 | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-600057 | OS X Mountain Lion Update v10.8.5 (Combo) |
| PATCH-600058 | OS X Mountain Lion Update v10.8.5 |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234