CVE Vulnerabilities

CVE-2005-3390

Published: Nov 01, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a GLOBALS fileupload field.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp3.0 (including)3.0 (including)
PhpPhp3.0.1 (including)3.0.1 (including)
PhpPhp3.0.2 (including)3.0.2 (including)
PhpPhp3.0.3 (including)3.0.3 (including)
PhpPhp3.0.4 (including)3.0.4 (including)
PhpPhp3.0.5 (including)3.0.5 (including)
PhpPhp3.0.6 (including)3.0.6 (including)
PhpPhp3.0.7 (including)3.0.7 (including)
PhpPhp3.0.8 (including)3.0.8 (including)
PhpPhp3.0.9 (including)3.0.9 (including)
PhpPhp3.0.10 (including)3.0.10 (including)
PhpPhp3.0.11 (including)3.0.11 (including)
PhpPhp3.0.12 (including)3.0.12 (including)
PhpPhp3.0.13 (including)3.0.13 (including)
PhpPhp3.0.14 (including)3.0.14 (including)
PhpPhp3.0.15 (including)3.0.15 (including)
PhpPhp3.0.16 (including)3.0.16 (including)
PhpPhp3.0.17 (including)3.0.17 (including)
PhpPhp3.0.18 (including)3.0.18 (including)
PhpPhp4.0.0 (including)4.0.0 (including)
PhpPhp4.0.1 (including)4.0.1 (including)
PhpPhp4.0.1-patch1 (including)4.0.1-patch1 (including)
PhpPhp4.0.1-patch2 (including)4.0.1-patch2 (including)
PhpPhp4.0.2 (including)4.0.2 (including)
PhpPhp4.0.3 (including)4.0.3 (including)
PhpPhp4.0.3-patch1 (including)4.0.3-patch1 (including)
PhpPhp4.0.4 (including)4.0.4 (including)
PhpPhp4.0.5 (including)4.0.5 (including)
PhpPhp4.0.6 (including)4.0.6 (including)
PhpPhp4.0.7 (including)4.0.7 (including)
PhpPhp4.0.7-rc1 (including)4.0.7-rc1 (including)
PhpPhp4.0.7-rc2 (including)4.0.7-rc2 (including)
PhpPhp4.0.7-rc3 (including)4.0.7-rc3 (including)
PhpPhp4.1.0 (including)4.1.0 (including)
PhpPhp4.1.1 (including)4.1.1 (including)
PhpPhp4.1.2 (including)4.1.2 (including)
PhpPhp4.2 (including)4.2 (including)
PhpPhp4.2.0 (including)4.2.0 (including)
PhpPhp4.2.1 (including)4.2.1 (including)
PhpPhp4.2.2 (including)4.2.2 (including)
PhpPhp4.2.3 (including)4.2.3 (including)
PhpPhp4.3.0 (including)4.3.0 (including)
PhpPhp4.3.1 (including)4.3.1 (including)
PhpPhp4.3.2 (including)4.3.2 (including)
PhpPhp4.3.3 (including)4.3.3 (including)
PhpPhp4.3.4 (including)4.3.4 (including)
PhpPhp4.3.5 (including)4.3.5 (including)
PhpPhp4.3.6 (including)4.3.6 (including)
PhpPhp4.3.7 (including)4.3.7 (including)
PhpPhp4.3.8 (including)4.3.8 (including)
PhpPhp4.3.9 (including)4.3.9 (including)
PhpPhp4.3.10 (including)4.3.10 (including)
PhpPhp4.3.11 (including)4.3.11 (including)
PhpPhp4.4.0 (including)4.4.0 (including)
PhpPhp5.0-rc1 (including)5.0-rc1 (including)
PhpPhp5.0-rc2 (including)5.0-rc2 (including)
PhpPhp5.0-rc3 (including)5.0-rc3 (including)
PhpPhp5.0.0 (including)5.0.0 (including)
PhpPhp5.0.1 (including)5.0.1 (including)
PhpPhp5.0.2 (including)5.0.2 (including)
PhpPhp5.0.3 (including)5.0.3 (including)
PhpPhp5.0.4 (including)5.0.4 (including)
PhpPhp5.0.5 (including)5.0.5 (including)
Red Hat Enterprise Linux 3RedHatphp-0:4.3.2-26.ent*
Red Hat Enterprise Linux 4RedHatphp-0:4.3.9-3.9*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
Red Hat Stronghold 4RedHat*
Stronghold 4.0 for Red Hat Enterprise Linux AS (version 2.1)RedHat*
Php4Ubuntudapper*
Php4Ubuntuedgy*
Php5Ubuntudapper*
Php5Ubuntudevel*
Php5Ubuntuedgy*
Php5Ubuntufeisty*

References