rfc1867.c in PHP prior to 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
php php |