PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.
                
            References
                    Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2009-11-23 16:30
Updated : 2018-10-10 12:48
NVD link : CVE-2009-4017
Mitre link : CVE-2009-4017
JSON object : View
CWE
                Products Affected
                php
- php
 


