vendor:
PHP
by:
SecurityFocus
3.3
CVSS
MEDIUM
Open_basedir Check Vulnerability
22
CWE
Product Name: PHP
Affected Version From: All
Affected Version To: All
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, and many Unix based operating systems
2002
PHP move_uploaded_file Function Open_basedir Check Vulnerability
It has been reported that the move_uploaded_file function lacks an open_basedir check. The effect of this issue is that this function may be used to perform file operations on directories outside of those specified by the open_basedir setting. This vulnerability may not be exploited to overwrite existing files.
Mitigation:
Ensure that the open_basedir setting is properly configured to restrict access to the intended directories.