Field Assessment
AI analysis pending.
CVE
CVE-2010-1129
Severity
HIGH
CVSS
7.5
EPSS
2.54%
Original Filing — NVD Description
The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.