Vulnerability record · CVE-2005-3390 · published 1 November 2005
CVE-2005-3390: PHP RFC1867 file upload allows GLOBALS array overwrite
Php · Php
PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, lets a remote attacker overwrite the GLOBALS array through a multipart/form-data POST request containing a fileupload field named GLOBALS. This breaks the assumption that GLOBALS is read-only and can defeat application-level security checks, so any affected PHP application relying on register_globals is exposed.
Description
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote variable overwrite with high EPSS and broad legacy PHP exposure, though exploitation depends on register_globals being enabled.
What it is
PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, lets a remote attacker overwrite the GLOBALS array through a multipart/form-data POST request containing a fileupload field named GLOBALS. This breaks the assumption that GLOBALS is read-only and can defeat application-level security checks, so any affected PHP application relying on register_globals is exposed.
Impact
An attacker can inject or overwrite global variables and the GLOBALS array, potentially bypassing authentication, authorization or input-validation logic in the hosted application. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reachable over the network via an unauthenticated HTTP POST with multipart/form-data to any PHP script that processes file uploads. No credentials or user interaction are required, but the flaw only applies when register_globals is enabled.
Exploitation
Not listed in CISA KEV and no ransomware usage documented. EPSS is high (0.655, 99.2nd percentile), and references include vendor patch and advisory tags, indicating public technical detail and fixes rather than confirmed in-the-wild exploitation.
What to do
- Upgrade PHP to 4.4.1 or 5.0.6 (or later) per the vendor release notes and distribution advisories.
- Disable register_globals in php.ini; this configuration is the precondition for the flaw.
- Apply the relevant OS vendor errata (Red Hat, Fedora Legacy, Gentoo, Mandriva, Novell, OpenPKG, Avaya) if upgrading PHP directly is not possible.
- Audit application code for reliance on register_globals and replace it with explicit superglobal access.
- Restrict or disable file upload handling on legacy PHP deployments that cannot be patched.
Detection
- Search web logs for multipart/form-data POST requests containing a fileupload field named GLOBALS.
- Monitor for unexpected changes to global variables or authentication state in PHP application logs.
- Inventory PHP versions and php.ini settings to find hosts running 4.x <= 4.4.0 or 5.x <= 5.0.5 with register_globals enabled.
- Review IDS/WAF rules for GLOBALS parameter injection in upload requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-3390 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-3390), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.