PublicDate: 2007-02-13 23:28:00 UTC Candidate: CVE-2007-0905 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0905 Description: PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: upstream_php5: released (5.2.0) dapper_php5: not-affected (5.2.0 only) edgy_php5: not-affected (5.2.0 only) feisty_php5: released (5.2.1-0ubuntu1.4) devel_php5: not-affected