Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qxh9-g3ww-hcvc

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

EPSS

Процентиль: 83%
0.021
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 14 лет назад

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

redhat
больше 18 лет назад

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

nvd
больше 14 лет назад

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

debian
больше 14 лет назад

PHP before 5.3.4 accepts the \0 character in a pathname, which might a ...

CVSS3: 3.7
fstec
больше 14 лет назад

Уязвимость функции file_exists интерпретатора языка программирования PHP, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 83%
0.021
Низкий

Дефекты

CWE-20