Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2202

Опубликовано: 16 июн. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4

Описание

The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."

РелизСтатусПримечание
devel

not-affected

5.3.6-13ubuntu1
hardy

released

5.2.4-2ubuntu5.18
lucid

released

5.3.2-1ubuntu4.10
maverick

released

5.3.3-1ubuntu9.6
natty

released

5.3.5-1ubuntu7.3
oneiric

not-affected

5.3.6-13ubuntu1
upstream

released

5.3.6-12

Показывать по

EPSS

Процентиль: 92%
0.08979
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."

nvd
около 14 лет назад

The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."

debian
около 14 лет назад

The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3. ...

github
около 3 лет назад

The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."

oracle-oval
больше 13 лет назад

ELSA-2012-0033: php security update (MODERATE)

EPSS

Процентиль: 92%
0.08979
Низкий

6.4 Medium

CVSS2