PHP Arbitrary File Upload

Medium Nessus Network Monitor Plugin ID 2286

Synopsis

The remote host is vulnerable to a an arbitrary file upload flaw.

Description

The remote web server is configured to be PHP-enabled. It is reported that versions of PHP up to 5.0.2 and 4.3.9 are prone to a file upload vulnerability. An attacker may upload an arbitrary file on the web server in the context of the PHP application.

Solution

Upgrade to version 4.3.9, 5.0.2 or higher.

See Also

http://php.net/ChangeLog-4.php

Plugin Details

Severity: Medium

ID: 2286

Family: Web Servers

Published: 2004/08/20

Modified: 2016/01/21

Dependencies: 8728, 8682

Nessus ID: 14770

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 6.4

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Temporal Vector: CVSS2#E:H/RL:OF/RC:C

CVSSv3

Base Score: 6.5

Temporal Score: 6.2

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS3#E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:php:php

Patch Publication Date: 2004/08/24

Vulnerability Publication Date: 2004/08/24

Reference Information

BID: 11190