VDB
CVE-2004-1392
CVE-2004-1392
PUBLISHED
Reported by mitre · Published February 6, 2005
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, * |
Timeline
- Dec 31, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- May 29, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- php-openbasedir-restriction-bypass(17900) vdb-entryx_refsource_XF
- RHSA-2005:406 vendor-advisoryx_refsource_REDHAT
- 11557 vdb-entryx_refsource_BID
- 20050120 [USN-66-1] PHP vulnerabilities mailing-listx_refsource_BUGTRAQ
- oval:org.mitre.oval:def:9279 vdb-entrysignaturex_refsource_OVAL
- FLSA:2344 vendor-advisoryx_refsource_FEDORA
- 1011984 vdb-entryx_refsource_SECTRACK
- 20041027 PHP4 cURL functions bypass open_basedir mailing-listx_refsource_BUGTRAQ
- RHSA-2005:405 vendor-advisoryx_refsource_REDHAT