Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 12 Jun 2011 12:20:06 -0300
From: Felipe Pena <>
Subject: CVE Request: PHP File upload filename

Please assign a CVE id for "File path injection vulnerability in RFC1867
File upload filename" [1].

The fix for the bug has been already committed. [2]

Reported by: Krzysztof Kotowicz <kkotowicz at gmail dot com>

[1] -
[2] -


Felipe Pena

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ