Vulnerability Name: | CVE-2004-1392 (CCN-17900) | ||||||||||||||||
Assigned: | 2004-10-27 | ||||||||||||||||
Published: | 2004-10-27 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Oct 27 2004 - 11:26:23 CDT PHP4 cURL functions bypass open_basedir Source: MITRE Type: CNA CVE-2004-1392 Source: BUGTRAQ Type: UNKNOWN 20041027 PHP4 cURL functions bypass open_basedir Source: BUGTRAQ Type: UNKNOWN 20050120 [USN-66-1] PHP vulnerabilities Source: CCN Type: RHSA-2005-405 PHP security update Source: CCN Type: RHSA-2005-406 PHP security update Source: CCN Type: SECTRACK ID: 1011984 PHP cURL Functions Let Scripts Byass the `open_basedir` Directory Restrictions Source: SECTRACK Type: Exploit 1011984 Source: CCN Type: CIAC INFORMATION BULLETIN P-197 PHP Security Bugs Source: REDHAT Type: UNKNOWN RHSA-2005:405 Source: REDHAT Type: UNKNOWN RHSA-2005:406 Source: BID Type: Exploit, Patch 11557 Source: CCN Type: BID-11557 PHP cURL Open_Basedir Restriction Bypass Vulnerability Source: CCN Type: USN-66-1 PHP vulnerabilities Source: CCN Type: USN-66-2 PHP vulnerability Source: FEDORA Type: Patch FLSA:2344 Source: XF Type: UNKNOWN php-openbasedir-restriction-bypass(17900) Source: XF Type: UNKNOWN php-openbasedir-restriction-bypass(17900) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9279 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |