AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-5624

HIGH · CVSS 7.5 EPSS 2.22%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-12-17 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. See the original NVD description below for full technical details.

CVE
CVE-2008-5624
Severity
HIGH
CVSS
7.5
EPSS
2.22%

Original NVD Description

PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable.