CVE-2015-2348
published 2015-03-30CVE-2015-2348: The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname…
PriorityP433medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
8.59%
94.5th percentile
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.5 | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| php | php | <= 5.4.38 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv6.8MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x58x-2jp5-xfv7: The move_uploaded_file implementation in ext/standard/basic_functions
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2015-2348 [MEDIUM] GHSA-x58x-2jp5-xfv7: The move_uploaded_file implementation in ext/standard/basic_functions
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
OSV
php5 vulnerabilities
osv·2015-04-20·CVSS 6.8
CVE-2015-3330 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
It was discovered that PHP incorrectly handled cleanup when used with
Apache 2.4. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-3330)
It was discovered that PHP incorrectly handled opening tar, zip or phar
archives through the PHAR extension. A remote attacker could use this issue
to cause PHP to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2015-3329)
It was discovered that PHP incorrectly handled regular expressions. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2015-2305)
Paulos Yibelo discovered that PHP incorrectly handled moving files when
OSV
CVE-2015-2348: The move_uploaded_file implementation in ext/standard/basic_functions
osv·2015-03-30·CVSS 5.0
CVE-2015-2348 [MEDIUM] CVE-2015-2348: The move_uploaded_file implementation in ext/standard/basic_functions
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2015-04-20·CVSS 6.8
CVE-2015-2305 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled cleanup when used with
Apache 2.4. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-3330)
It was discovered that PHP incorrectly handled opening tar, zip or phar
archives through the PHAR extension. A remote attacker could use this issue
to cause PHP to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2015-3329)
It was discovered that PHP incorrectly handled regular expressions. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2015-2305)
Paulos Yibelo
Red Hat
php: move_uploaded_file() NUL byte injection in file name
vendor_redhat·2015-03-02·CVSS 5.0
CVE-2015-2348 [MEDIUM] CWE-626 php: move_uploaded_file() NUL byte injection in file name
php: move_uploaded_file() NUL byte injection in file name
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
It was found that PHP move_uploaded_file() function did not properly handle file names with a NULL character. A remote attacker could possibly use this flaw to make a PHP script access unexpected files and bypass intended file system access restrictions.
Statement: This issue does not affect the current php and php53 pac
Apple
CVE-2015-2348: OS X El Capitan v10.11
vendor_apple·CVSS 5.0
CVE-2015-2348 [MEDIUM] CVE-2015-2348: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2015-2348
Component: CVE-2015-2348
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4025 php: CVE-2006-7243 regressions in 5.4+
bugzilla·2015-05-20·CVSS 5.0
CVE-2015-4025 [MEDIUM] CVE-2015-4025 php: CVE-2006-7243 regressions in 5.4+
CVE-2015-4025 php: CVE-2006-7243 regressions in 5.4+
Regressions of parts of the CVE-2006-7243 fix were found in PHP >= 5.4. This issue is similar to CVE-2015-2348 (bug 1207682) and CVE-2014-5120 (bug 1132793).
Upstream report:
https://bugs.php.net/bug.php?id=69418
Upstream fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=be9b2a95adb504abd5acdc092d770444ad6f6854
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1223447]
---
I noted CVE-2006-7243 (see bug 662707) regressions in PHP 5.4+ for the following functions in the upstream bug report:
- set_include_path()
- tempnam() - second argument only
- rmdir()
- readlink()
readlink() was already fixed in 5.4.40 / 5.5.24 / 5.6.8, see bug 1213407 comment 5.
Linked upstream commit includes additional fi
Bugzilla
CVE-2015-2348 php: restrictions bypass in move_uploaded_file implementation (incomplete fix for CVE-2006-7243) [fedora-all]
bugzilla·2015-03-31·CVSS 5.0
CVE-2015-2348 [MEDIUM] CVE-2015-2348 php: restrictions bypass in move_uploaded_file implementation (incomplete fix for CVE-2006-7243) [fedora-all]
CVE-2015-2348 php: restrictions bypass in move_uploaded_file implementation (incomplete fix for CVE-2006-7243) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2015-2348 php: move_uploaded_file() NUL byte injection in file name
bugzilla·2015-03-31·CVSS 5.0
CVE-2015-2348 [MEDIUM] CVE-2015-2348 php: move_uploaded_file() NUL byte injection in file name
CVE-2015-2348 php: move_uploaded_file() NUL byte injection in file name
Common Vulnerabilities and Exposures assigned an identifier CVE-2015-2348 to
the following vulnerability:
Name: CVE-2015-2348
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2348
Assigned: 20150319
Reference: https://bugs.php.net/bug.php?id=69207
The move_uploaded_file implementation in
ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before
5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering
a \x00 character, which allows remote attackers to bypass intended
extension restrictions and create files with unexpected names via a
crafted second argument. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2006-7243.
Discussion:
Created php tracking bugs for this
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=1291d6bbee93b6109eb07e8f7916ff1b7fcc13e1http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00015.htmlhttp://marc.info/?l=bugtraq&m=143748090628601&w=2http://marc.info/?l=bugtraq&m=144050155601375&w=2http://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2015-1053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1066.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1135.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/73434http://www.securitytracker.com/id/1032484http://www.ubuntu.com/usn/USN-2572-1https://bugs.php.net/bug.php?id=69207https://security.gentoo.org/glsa/201606-10https://support.apple.com/HT205267http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=1291d6bbee93b6109eb07e8f7916ff1b7fcc13e1http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00015.htmlhttp://marc.info/?l=bugtraq&m=143748090628601&w=2http://marc.info/?l=bugtraq&m=144050155601375&w=2http://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2015-1053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1066.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1135.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/73434http://www.securitytracker.com/id/1032484http://www.ubuntu.com/usn/USN-2572-1https://bugs.php.net/bug.php?id=69207https://security.gentoo.org/glsa/201606-10https://support.apple.com/HT205267
2015-03-30
Published