5.8
CVSSv2

CVE-2012-1172

Published: 24/05/2012 Updated: 18/01/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The file-upload implementation in rfc1867.c in PHP prior to 5.4.0 does not properly handle invalid [ (open square bracket) characters in name values, which makes it easier for remote malicious users to cause a denial of service (malformed $_FILES indexes) or conduct directory traversal attacks during multi-file uploads by leveraging a script that lacks its own filename restrictions.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.3.3

php php 5.3.2

php php 5.2.5

php php 5.2.11

php php 5.2.0

php php 5.3.0

php php 5.3.1

php php 5.3.5

php php 5.2.6

php php 5.2.9

php php 5.2.17

php php 5.2.10

php php 5.1.1

php php 5.1.0

php php 5.1.6

php php 5.0.3

php php 5.0.0

php php 5.2.3

php php 5.2.4

php php 5.2.14

php php 5.0.2

php php 5.3.7

php php 5.3.6

php php 5.2.7

php php 5.2.8

php php 5.2.1

php php 5.2.2

php php 5.1.3

php php 5.1.2

php php 5.0.5

php php 5.0.4

php php 5.0.1

php php

php php 5.3.8

php php 5.3.4

php php 5.3.9

php php 5.2.12

php php 5.2.13

php php 5.2.15

php php 5.2.16

php php 5.1.4

php php 5.1.5

Vendor Advisories

Debian Bug report logs - #663760 [CVE-2012-1172] PHP 53x Corrupted $_FILES indices lead to security concern Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Tu ...
Several security issues were fixed in PHP ...
Synopsis Moderate: php security update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Scori ...
Synopsis Moderate: php security update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Scori ...
Synopsis Moderate: php53 security update Type/Severity Security Advisory: Moderate Topic Updated php53 packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability S ...
De Eindbazen discovered that PHP, when run with mod_cgi, will interpret a query string as command line parameters, allowing to execute arbitrary code Additionally, this update fixes insufficient validation of upload name which lead to corrupted $_FILES indices For the stable distribution (squeeze), this problem has been fixed in version 533-7+s ...