| CVE-ID |
CVE-2004-1020
|
• CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
|
| Description |
| The addslashes function in PHP 4.3.9 does not properly escape a NULL
(/0) character, which may allow remote attackers to read arbitrary
files in PHP applications that contain a directory traversal
vulnerability in require or include statements, but are otherwise
protected by the magic_quotes_gpc mechanism. NOTE: this issue was
originally REJECTed by its CNA before publication, but that decision
is in active dispute. This candidate may change significantly in the
future as a result of further discussion.
|
| References |
|
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
|
|
|
| Assigning CNA |
| N/A |
| Date Entry Created |
| 20041104 |
Disclaimer: The entry creation date may reflect when
the CVE ID was allocated or reserved, and does not
necessarily indicate when this vulnerability was
discovered, shared with the affected vendor, publicly
disclosed, or updated in CVE.
|
| Phase (Legacy) |
| Assigned (20041104) |
| Votes (Legacy) |
REVIEWING(1) Christey
|
| Comments (Legacy) |
Christey> There is active disagreement regarding whether this satisfies the
criteria for inclusion in CVE, because the attack vectors require
function parameters that are typically controlled only by the
application developer, not an external attacker. This would mean that
only the PHP application owner could exploit it.
Since the application developer presumably already has acccess
to the underlying file system, directory traversal attacks provide no
additional access to the application owner. Therefore, this candidate
would only be valid if there are cases in which the attacker can
inject a null character into a string that is processed by addslashes.
|
| Proposed (Legacy) |
| N/A |
|
This is an entry on the CVE List, which provides common identifiers for publicly known cybersecurity vulnerabilities. |
|
|
|
For More Information: cve@mitre.org
|