Search

published date: November 14, 2000

CVE-2000-0860 : File Upload Vulnerability

Description

The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.

Product(s):

  • PHP PHP_FI 1.0
  • PHP 1.0 Beta1
  • PHP 1.0 Beta2
  • PHP 1.0 Beta3
  • PHP 1.0 Release Candidate 1
  • PHP 1.0 Release Candidate 2

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2000-0860, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2000-0860 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?