Description
The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Post Type UI Cross-Site Scripting (1.0.6)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2079)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1559)
Oracle Database Server Create Session privilege issue (CVE-2021-1993)