CVE-2008-5844
Summary
| CVE | CVE-2008-5844 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-01-05 20:30:02 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes_gpc regardless of the actual magic_quotes_gpc setting, which might make it easier for context-dependent attackers to conduct SQL injection attacks and unspecified other attacks. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP Bugs: #42718: FILTER_UNSAFE_RAW not applied when configured as default filter, even with flags | af854a3a-2127-422b-91ae-364da2661108 | bugs.php.net | Exploit |
| PHP: PHP 5 ChangeLog | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | |
| PHP: News Archive - 2008 | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | |
| PHP Bugs: #46759: magic_quotes_gpc doesn't work | af854a3a-2127-422b-91ae-364da2661108 | bugs.php.net | |
| PHP magic_quotes_gpc() Error May Let Users Bypass Security Filtering - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| PHP: News Archive - 2008 | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | |
| PHP 5.2.7 'magic_quotes_gpc' Security Bypass Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-01-23 | Tomas Hoger | Not vulnerable. This issue did not affect the versions of the php package, as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5, and with Red Hat Application Stack v1 and v2. Only PHP version 5.2.7 was affected by this flaw. |
There are currently no legacy QID mappings associated with this CVE.