CVE-2004-1392
Publication date 31 December 2004
Last updated 17 July 2025
Ubuntu priority
Description
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.