CVE-2005-3390
CVE-2005-3390
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/26443unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522http://rhn.redhat.com/errata/RHSA-2006-0549.htmlhttp://secunia.com/advisories/17371http://secunia.com/advisories/17490http://secunia.com/advisories/17510http://secunia.com/advisories/17531http://secunia.com/advisories/17557http://secunia.com/advisories/17559http://secunia.com/advisories/18054http://secunia.com/advisories/18198http://secunia.com/advisories/18669http://secunia.com/advisories/21252