← All CVEs

CVE-2009-4017

medium · 5

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.

5
CVSS
12.0%
EPSS (exploit prob.)
96th
EPSS percentile
2009-11-24
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-770

Affected products

VendorProductAffected versions
phpphp< 5.2.12
phpphp5.3.0
phpphp5.3.0
phpphp5.3.0
phpphp5.3.0
phpphp5.3.0
phpphp5.3.0
phpphp5.3.0
phpphp5.3.0
phpphp5.3.0
applemac_os_x10.6.3
debiandebian_linux4.0
debiandebian_linux5.0
debiandebian_linux6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-4017