AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2004-2692

HIGH · CVSS 9.3 EPSS 4.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2004-12-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2004-2692
Severity
HIGH
CVSS
9.3
EPSS
4.51%

Original NVD Description

The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function.