CVE-2008-1614

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
02/04/2008
Last modified:
09/04/2025

Description

suPHP before 0.6.3 allows local users to gain privileges via (1) a race condition that involves multiple symlink changes to point a file owned by a different user, or (2) a symlink to the directory of a different user, which is used to determine privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sebastian_marsching:suphp:*:*:*:*:*:*:*:* 0.6.2 (including)