Description
PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.
Remediation
References
Related Vulnerabilities
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2026-28782)
WordPress Plugin SB Welcome Email Editor Unspecified Vulnerability (4.1)
Squid Out-of-bounds Write Vulnerability (CVE-2025-54574)
Perl Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2018-12015)
WordPress Plugin File Manager Pro Arbitrary File Upload (8.3.4)