CVE-2004-0959: Low severity PHP PHP vulnerability
Published Oct 16, 2004
·Updated
rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$FILES" array to be modified.
Affected Software
1 affected component
PHP PHP<=5.0.2
Remediation
Patch Available
Event History
Oct 16, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0959?
CVE-2004-0959 is considered a moderate severity vulnerability due to its potential for local users to exploit file upload capabilities.
2
How do I fix CVE-2004-0959?
To fix CVE-2004-0959, update PHP to version 5.0.3 or later.
3
What systems are affected by CVE-2004-0959?
CVE-2004-0959 affects PHP versions prior to 5.0.3.
4
Can CVE-2004-0959 be exploited remotely?
CVE-2004-0959 is primarily a local vulnerability and requires local user access to exploit.
5
What type of attacks does CVE-2004-0959 enable?
CVE-2004-0959 enables local users to upload files to arbitrary locations on the server.