PHP upload arbitrary file disclosure vulnerability

PHP upload arbitrary file disclosure vulnerability

Published on 2004-03-27. Updated on 2007-03-20.

Description:

This alert was generated using only banner information. It may be a false positive.

PHP applications can be manipulated into opening arbitrary files on the server, rather than those uploaded by the user.

Affected PHP versions (up to 3.0.16, 4.0.2).

Impact:
Allow remote attackers to read any file located on the server which is readable by a user of the server's privilege level.

Recommendation:
Upgrade PHP to the latest version.

Tags: Scripts

Alert Tags: configuration
ApplicableApplicationServer : PHP
ApplicableOS: All
ApplicableWebServer: All

References:

  • BID 1649
  • PHP Homepage

  • Go Back