{"api_version":"1","generated_at":"2026-07-23T09:29:50+00:00","cve":"CVE-2008-5844","urls":{"html":"https://cve.report/CVE-2008-5844","api":"https://cve.report/api/cve/CVE-2008-5844.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5844","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5844"},"summary":{"title":"CVE-2008-5844","description":"PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes_gpc regardless of the actual magic_quotes_gpc setting, which might make it easier for context-dependent attackers to conduct SQL injection attacks and unspecified other attacks.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-01-05 20:30:02","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-16","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://bugs.php.net/bug.php?id=42718","name":"http://bugs.php.net/bug.php?id=42718","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"PHP Bugs: #42718: FILTER_UNSAFE_RAW not applied when configured as default filter, even with flags","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.php.net/ChangeLog-5.php#5.2.8","name":"http://www.php.net/ChangeLog-5.php#5.2.8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP: PHP 5 ChangeLog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.php.net/archive/2008.php#id2008-12-08-1","name":"http://www.php.net/archive/2008.php#id2008-12-08-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP: News Archive - 2008","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.php.net/bug.php?id=46759","name":"http://bugs.php.net/bug.php?id=46759","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP Bugs: #46759: magic_quotes_gpc doesn't work","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1021393","name":"http://www.securitytracker.com/id?1021393","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP magic_quotes_gpc() Error May Let Users Bypass Security Filtering - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.php.net/archive/2008.php#id2008-12-07-1","name":"http://www.php.net/archive/2008.php#id2008-12-07-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP: News Archive - 2008","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/32673","name":"http://www.securityfocus.com/bid/32673","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP 5.2.7 'magic_quotes_gpc' Security Bypass Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5844","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5844","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5844","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"5.2.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2008-5844","organization":"Red Hat","lastmodified":"2009-01-23","contributor":"Tomas Hoger","statementText":"Not vulnerable. This issue did not affect the versions of the php package, as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5, and with Red Hat Application Stack v1 and v2. Only PHP version 5.2.7 was affected by this flaw.","cve_year":"2008","cve_id":"5844","crc32":"140cab77"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T11:04:44.796Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.php.net/archive/2008.php#id2008-12-08-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.php.net/archive/2008.php#id2008-12-07-1"},{"name":"1021393","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1021393"},{"name":"32673","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32673"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.php.net/ChangeLog-5.php#5.2.8"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.php.net/bug.php?id=46759"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.php.net/bug.php?id=42718"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-12-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes_gpc regardless of the actual magic_quotes_gpc setting, which might make it easier for context-dependent attackers to conduct SQL injection attacks and unspecified other attacks."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-01-09T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.php.net/archive/2008.php#id2008-12-08-1"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.php.net/archive/2008.php#id2008-12-07-1"},{"name":"1021393","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1021393"},{"name":"32673","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32673"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.php.net/ChangeLog-5.php#5.2.8"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.php.net/bug.php?id=46759"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.php.net/bug.php?id=42718"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5844","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes_gpc regardless of the actual magic_quotes_gpc setting, which might make it easier for context-dependent attackers to conduct SQL injection attacks and unspecified other attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.php.net/archive/2008.php#id2008-12-08-1","refsource":"CONFIRM","url":"http://www.php.net/archive/2008.php#id2008-12-08-1"},{"name":"http://www.php.net/archive/2008.php#id2008-12-07-1","refsource":"CONFIRM","url":"http://www.php.net/archive/2008.php#id2008-12-07-1"},{"name":"1021393","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1021393"},{"name":"32673","refsource":"BID","url":"http://www.securityfocus.com/bid/32673"},{"name":"http://www.php.net/ChangeLog-5.php#5.2.8","refsource":"CONFIRM","url":"http://www.php.net/ChangeLog-5.php#5.2.8"},{"name":"http://bugs.php.net/bug.php?id=46759","refsource":"CONFIRM","url":"http://bugs.php.net/bug.php?id=46759"},{"name":"http://bugs.php.net/bug.php?id=42718","refsource":"CONFIRM","url":"http://bugs.php.net/bug.php?id=42718"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5844","datePublished":"2009-01-05T20:00:00.000Z","dateReserved":"2009-01-05T00:00:00.000Z","dateUpdated":"2024-08-07T11:04:44.796Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-01-05 20:30:02","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-16","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:5.2.7:*:*:*:*:*:*:*","matchCriteriaId":"1C0E7E2A-4770-4B68-B74C-5F5A6E1876DC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5844","Ordinal":"1","Title":"CVE-2008-5844","CVE":"CVE-2008-5844","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5844","Ordinal":"1","NoteData":"PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes_gpc regardless of the actual magic_quotes_gpc setting, which might make it easier for context-dependent attackers to conduct SQL injection attacks and unspecified other attacks.","Type":"Description","Title":"CVE-2008-5844"},{"CveYear":"2008","CveId":"5844","Ordinal":"2","NoteData":"2009-01-05","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"5844","Ordinal":"3","NoteData":"2009-01-09","Type":"Other","Title":"Modified"}]}}}