Release Date: | 2015-03-02 | |
Impact: | Moderate | What is this? |
The move_uploaded_file implementation inext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
See more information about CVE-2015-2348 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
Base Score: | 4.0 |
Vector String: | AV:N/AC:H/Au:N/C:P/I:N/A:P |
Version: | 2.0 |
Attack Vector: | Network |
Attack Complexity: | High |
Authentication: | None |
Confidentiality Impact: | Partial |
Integrity Impact: | None |
Availability Impact: | Partial |
Platform | Errata | Release Date |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: