5

CVE-2000-0860

Exploit
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version 1.0
Php ≫ Php Version 2.0
Php ≫ Php Version 2.0b10
Php ≫ Php Version 3.0
Php ≫ Php Version 3.0.1
Php ≫ Php Version 3.0.2
Php ≫ Php Version 3.0.3
Php ≫ Php Version 3.0.4
Php ≫ Php Version 3.0.5
Php ≫ Php Version 3.0.6
Php ≫ Php Version 3.0.7
Php ≫ Php Version 3.0.8
Php ≫ Php Version 3.0.9
Php ≫ Php Version 3.0.10
Php ≫ Php Version 3.0.11
Php ≫ Php Version 3.0.12
Php ≫ Php Version 3.0.13
Php ≫ Php Version 4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.75% 0.847
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2000-08/0455.html
Vendor Advisory
http://archives.neohapsis.com/archives/bugtraq/2000-08/0477.html
http://archives.neohapsis.com/archives/bugtraq/2000-09/0150.html
http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&tr1=1.1&r2=text&tr2=1.45&diff_format=u
http://www.securityfocus.com/bid/1649
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/5190