PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-11-23 16:30
Updated : 2018-10-10 12:48
NVD link : CVE-2009-4017
Mitre link : CVE-2009-4017
JSON object : View
CWE
Products Affected
php
- php