CVE Vulnerabilities

CVE-2004-1392

Published: Dec 31, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

Affected Software

Name Vendor Start Version End Version
Php Php 4.0 4.0
Php Php 4.0.1 4.0.1
Php Php 4.0.1 4.0.1
Php Php 4.0.1 4.0.1
Php Php 4.0.2 4.0.2
Php Php 4.0.3 4.0.3
Php Php 4.0.3 4.0.3
Php Php 4.0.4 4.0.4
Php Php 4.0.5 4.0.5
Php Php 4.0.6 4.0.6
Php Php 4.0.7 4.0.7
Php Php 4.0.7 4.0.7
Php Php 4.0.7 4.0.7
Php Php 4.0.7 4.0.7
Red Hat Enterprise Linux 3 RedHat php-0:4.3.2-23.ent *
Red Hat Enterprise Linux 4 RedHat php-0:4.3.9-3.6 *
Php4 Ubuntu dapper *
Php4 Ubuntu edgy *
Php5 Ubuntu dapper *
Php5 Ubuntu devel *
Php5 Ubuntu edgy *
Php5 Ubuntu feisty *

References