#VU110553 Input validation error in PHP - CVE-2000-0059

 

#VU110553 Input validation error in PHP - CVE-2000-0059

Published: September 10, 2008 / Updated: June 10, 2025


Vulnerability identifier: #VU110553
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2000-0059
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
PHP
Software vendor:
PHP Group

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.


Remediation

Install update from vendor's website.

External links