VDB
CVE-2004-0959
CVE-2004-0959
PUBLISHED
CVSS 2.0999999046325684 LOW
rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.
EPSS 0.58% · 44.4th percentile
Risk Scores
CVSS 2.0
2.0999999046325684
EPSS Score
0.58%
44.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| php | php | 0 |
| n/a | n/a | n/a |
Timeline
- Oct 16, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- php-mime-array-execute-code(17392) vdb
- oval:org.mitre.oval:def:10961 vdb
- 1011307 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2004-0959 advisory
- http://secunia.com/advisories/12560 url
- http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0054.html technical
- http://marc.info/?l=bugtraq&m=109534848430404&w=2 technical
- http://secunia.com/advisories/12560/ technical
- http://www.redhat.com/support/errata/RHSA-2004-687.html patch
- https://bugzilla.fedora.us/show_bug.cgi?id=2344 technical