Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP Remote Arbitrary Location File Upload Vulnerability

Reportedly PHP is vulnerable to an arbitrary location file upload vulnerability. This issue is due to a failure of the PHP application to properly sanitize user-supplied file name input.

An attacker may exploit this issue to upload files to an arbitrary location on a computer running the affected software. This may facilitate arbitrary server-side script code execution as well as other attacks.

It is reported that this issue only affects PHP versions 4.2.0 and subsequent.







 

Privacy Statement
Copyright 2008, SecurityFocus