VDB
CVE-2004-0959
CVE-2004-0959
PUBLISHED
CVSS 2.0999999046325684 LOW
rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.
EPSS 4.81% · 89.7th percentile
Risk Scores
CVSS 2.0
2.0999999046325684
EPSS Score
4.81%
89.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| php | php | 0 |
| n/a | n/a | n/a |
Exploit Intelligence
- oval:org.mitre.oval:def:10961 (circl)
- php-mime-array-execute-code(17392) (circl)
- 1011307 (circl)
- 12560 (circl)
- 20040915 Php Vulnerability N. 2 (circl)
- FLSA:2344 (circl)
- 20040915 Php Vulnerability N. 2 (circl)
- RHSA-2004:687 (circl)
Timeline
- Oct 16, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- oval:org.mitre.oval:def:10961 vdb
- php-mime-array-execute-code(17392) vdb
- 1011307 vdb
- 12560 third-party-advisory
- 20040915 Php Vulnerability N. 2 mailing-list
- FLSA:2344 vendor-advisory
- 20040915 Php Vulnerability N. 2 mailing-list
- RHSA-2004:687 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0959 advisory
- http://secunia.com/advisories/12560 url