bugs.php.netConfirmation
http://bugs.php.net/bug.php?id=16128 CVE-2002-0484
PHP 3.0.x/4.x - Move_Uploaded_File open_basedir Circumvention
Record summary
CVE-2002-0484 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP 3.0.x/4.x - Move_Uploaded_File open_basedir CircumventionExploitDB exploitby TozzNot analyzed1 file
References
720020322 Re: move_uploaded_file breaks safe_mode restrictions in PHPmailing list
http://marc.info/?l=bugtraq&m=101683938806677&w=2 20020317 move_uploaded_file breaks safe_mode restrictions in PHPmailing list
http://online.securityfocus.com/archive/1/262999 20020321 Re: move_uploaded_file breaks safe_mode restrictions in PHPmailing list
http://online.securityfocus.com/archive/1/263259 php-moveuploadedfile-create-files(8591)vdb entry
http://www.iss.net/security_center/static/8591.php 4325vdb entry
http://www.securityfocus.com/bid/4325 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0484