Vulnerability Name: | CVE-2002-0484 (CCN-8591) |
Assigned: | 2002-03-17 |
Published: | 2002-03-17 |
Updated: | 2016-10-18 |
Summary: | move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | File Manipulation |
References: | Source: CCN Type: BugTraq Mailing List, Sun Mar 17 2002 - 16:23:34 CST move_uploaded_file breaks safe_mode restrictions in PHP
Source: CCN Type: BugTraq Mailing List, Thu Mar 21 2002 - 03:55:18 CST move_uploaded_file breaks safe_mode restrictions in PHP
Source: CCN Type: PHP Bug #16128 move_uploaded_file breaks safe_mode and open_basedir restrictions
Source: CONFIRM Type: UNKNOWN http://bugs.php.net/bug.php?id=16128
Source: MITRE Type: CNA CVE-2002-0484
Source: BUGTRAQ Type: UNKNOWN 20020322 Re: move_uploaded_file breaks safe_mode restrictions in PHP
Source: BUGTRAQ Type: Vendor Advisory 20020317 move_uploaded_file breaks safe_mode restrictions in PHP
Source: BUGTRAQ Type: Vendor Advisory 20020321 Re: move_uploaded_file breaks safe_mode restrictions in PHP
Source: XF Type: UNKNOWN php-moveuploadedfile-create-files(8591)
Source: CCN Type: OSVDB ID: 5282 PHP move_uploaded_file Function Arbitrary File Upload
Source: CCN Type: PHP Group Web site PHP: Hypertext Preprocessor
Source: BID Type: UNKNOWN 4325
Source: CCN Type: BID-4325 PHP Move_Uploaded_File Open_Basedir Circumvention Vulnerability
Source: XF Type: UNKNOWN php-moveuploadedfile-create-files(8591)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:php:php:3.0:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.1:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.2:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.3:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.4:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.5:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.6:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.7:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.8:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.9:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.10:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.11:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.12:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.13:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.14:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.15:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.16:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.17:*:*:*:*:*:*:*OR cpe:/a:php:php:3.0.18:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0.0:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0.1:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0.1:patch1:*:*:*:*:*:*OR cpe:/a:php:php:4.0.1:patch2:*:*:*:*:*:*OR cpe:/a:php:php:4.0.2:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0.3:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0.3:patch1:*:*:*:*:*:*OR cpe:/a:php:php:4.0.4:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0.5:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0.6:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0.7:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0.7:rc1:*:*:*:*:*:*OR cpe:/a:php:php:4.0.7:rc2:*:*:*:*:*:*OR cpe:/a:php:php:4.0.7:rc3:*:*:*:*:*:*OR cpe:/a:php:php:4.1.0:-:*:*:*:*:*:*OR cpe:/a:php:php:4.1.1:*:*:*:*:*:*:*OR cpe:/a:php:php:4.1.2:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:php:php:4.0.5:-:*:*:*:*:*:*OR cpe:/a:php:php:4.1.1:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0.0:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0.1:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0.2:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0.3:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0.4:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0.6:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0.7:-:*:*:*:*:*:*OR cpe:/a:php:php:4.0:beta_4_patch1:*:*:*:*:*:*OR cpe:/a:php:php:4.0:beta1:*:*:*:*:*:*OR cpe:/a:php:php:4.0:beta2:*:*:*:*:*:*OR cpe:/a:php:php:4.0:beta3:*:*:*:*:*:*OR cpe:/a:php:php:4.0:beta4:*:*:*:*:*:*OR cpe:/a:php:php:4.1.0:-:*:*:*:*:*:*OR cpe:/a:php:php:4.1.2:*:*:*:*:*:*:*OR cpe:/a:php:php:4.0:rc1:*:*:*:*:*:*OR cpe:/a:php:php:4.0:rc2:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |