AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-0754

MEDIUM · CVSS 4.4 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-02-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2011-0754
Severity
MEDIUM
CVSS
4.4
EPSS
0.34%
Windows

Original NVD Description

The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform differences in the stat structure, related to lack of a FILE_ATTRIBUTE_REPARSE_POINT check.