| Severity : |
Medium
|
| Published : |
2011-06-16
|
| Modified : |
2012-02-03
|
| Base Score : |
6.4
|
| Details : |
The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."
|
| Product/Version : |
Pro 4.x
CGE 4.x
Mobilinux 4.x
Pro 5.0
Mobilinux 5.0.24
MVL 5 Atom
Pro 5.0.24
MVL 5 OMAP3
MVL 5 OMAP3530
CGE 5.x
Mobilinux 5.x
|
|
CVE Vulnerabilities List CVE-2011