VULNERABILITY INTELLIGENCE

CVE-2004-1392

CVSS score5 MEDIUM
EPSS probability10.76%
CISA KEVNot currently listed
Published2004-12-31
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:P/I:N/A:N

Description

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

Primary references