Description
Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename.
Remediation
References
Related Vulnerabilities
WordPress Plugin Double Opt-In for Download Multiple Cross-Site Scripting Vulnerabilities (2.1.5)
Oracle Database Server CVE-2024-21233 Vulnerability (CVE-2024-21233)
Envoy Proxy Use After Free Vulnerability (CVE-2023-35943)
Ruby on Rails Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-0449)
WordPress Plugin Events Manager Cross-Site Scripting (5.8.1.1)