VULNERABILITY INTELLIGENCE

CVE-2002-0484

CVSS score5 MEDIUM
EPSS probability9.50%
CISA KEVNot currently listed
Published2002-08-12
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:N/I:P/A:N

Description

move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.

Primary references