move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/1/262999 | mailing list vendor advisory |
http://bugs.php.net/bug.php?id=16128 | |
http://www.iss.net/security_center/static/8591.php | vdb entry |
http://www.securityfocus.com/bid/4325 | vdb entry |
http://marc.info/?l=bugtraq&m=101683938806677&w=2 | mailing list |
http://online.securityfocus.com/archive/1/263259 | mailing list vendor advisory |