Sploitus

CVE-2004-1392

1 known exploit for CVE-2004-1392

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

Affected products
Php, Red Hat, Curl
Php
= 4.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7
CVSS 2.0
5.0 MEDIUM
EPSS
10.8% (96th percentile)
NVD status
Modified
Published
2005-02-06
CVE-2004-1392 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2004-1392

Proof-of-concept code and exploit modules indexed by Sploitus