Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Jun 16, 2026
CVE-2004-1392
CVE-2004-1392
Description
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
154.0+ 14 more
- (no CPE)range: 4.0
- cpe:2.3:a:php:php:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.3:patch1:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.7:rc1:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.7:rc2:*:*:*:*:*:*
- cpe:2.3:a:php:php:4.0.7:rc3:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- bugzilla.fedora.us/show_bug.cginvdPatch
- securitytracker.com/idnvdExploit
- www.securityfocus.com/bid/11557nvdExploitPatch
- marc.infonvd
- marc.infonvd
- www.redhat.com/support/errata/RHSA-2005-405.htmlnvd
- www.redhat.com/support/errata/RHSA-2005-406.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17900nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9279nvd
News mentions
0No linked articles in our index yet.