Vulnerabilities > CVE-2002-0484 - Unspecified vulnerability in PHP

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
php
exploit available

Summary

move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.

Exploit-Db

descriptionPHP 3.0.x/4.x Move_Uploaded_File Open_Basedir Circumvention Vulnerability. CVE-2002-0484. Local exploit for php platform
idEDB-ID:21347
last seen2016-02-02
modified2002-03-17
published2002-03-17
reporterTozz
sourcehttps://www.exploit-db.com/download/21347/
titlePHP 3.0.x/4.x Move_Uploaded_File Open_Basedir Circumvention Vulnerability