PHP Arbitrary File Upload

Medium Nessus Network Monitor Plugin ID 2286


The remote host is vulnerable to a an arbitrary file upload flaw.


The remote web server is configured to be PHP-enabled. It is reported that versions of PHP up to 5.0.2 and 4.3.9 are prone to a file upload vulnerability. An attacker may upload an arbitrary file on the web server in the context of the PHP application.


Upgrade to version 4.3.9, 5.0.2 or higher.

See Also

Plugin Details

Severity: Medium

ID: 2286

Family: Web Servers

Published: 2004/08/20

Modified: 2016/01/21

Dependencies: 8728, 8682

Nessus ID: 14770

Risk Information

Risk Factor: Medium


Base Score: 6.4

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Temporal Vector: CVSS2#E:H/RL:OF/RC:C


Base Score: 6.5

Temporal Score: 6.2


Temporal Vector: CVSS3#E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:php:php

Patch Publication Date: 2004/08/24

Vulnerability Publication Date: 2004/08/24

Reference Information

BID: 11190