CVE-2004-1392
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
- Php
- = 4.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 10.8% (96th percentile)
- NVD status
- Modified
- Published
- 2005-02-06
CVE-2004-1392 at NVD
1 known exploit for CVE-2004-1392
Proof-of-concept code and exploit modules indexed by Sploitus