CVE-2006-2825
cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive.
- Affected products
- Cpanel
- Cpanel
- All versions
- CVSS 2.0
- 5.1 MEDIUM
- EPSS
- 1.2% (66th percentile)
- NVD status
- Modified
- Published
- 2006-06-05
CVE-2006-2825 at NVD
No indexed exploits for CVE-2006-2825 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2006-2825 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.