20041027 PHP4 cURL functions bypass open_basedirmailing list
http://marc.info/?l=bugtraq&m=109898213806099&w=2 CVE-2004-1392
PHP 4.x/5 - cURL 'open_basedir' Restriction Bypass
Record summary
CVE-2004-1392 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP 4.x/5 - cURL 'open_basedir' Restriction BypassExploitDB exploitby FraMeNot analyzed1 file
References
1020050120 [USN-66-1] PHP vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=110625060220934&w=2 1011984vdb entry
http://securitytracker.com/id?1011984 RHSA-2005:405Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-405.html RHSA-2005:406Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-406.html 11557vdb entry
http://www.securityfocus.com/bid/11557 FLSA:2344Vendor advisory
https://bugzilla.fedora.us/show_bug.cgi?id=2344 php-openbasedir-restriction-bypass(17900)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17900 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1392 oval:org.mitre.oval:def:9279vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9279