CVE-2004-0959

Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 16 Oct 2004, 04:00
Last modified:08 Aug 2024, 00:31

Vulnerability Summary

Overall Risk (default)
minimal
9/100
CVSS Score
2.1 LOW
v2.0 (nvd)
EPSS Score
4.81% LOW
5% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Oct 2004, 04:00
Published
Vulnerability first disclosed
08 Aug 2024, 00:31
Last Modified
Vulnerability information updated

Description

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

CVSS Metrics

  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 4.81% Percentile: 90%

Affected Systems

  • UnknownPHP

    ≤ 5.0.2

References (8)