← Vulnerability feed

Vulnerability record · CVE-2005-3390 · published 1 November 2005

CVE-2005-3390: PHP RFC1867 file upload allows GLOBALS array overwrite

Php · Php

PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, lets a remote attacker overwrite the GLOBALS array through a multipart/form-data POST request containing a fileupload field named GLOBALS. This breaks the assumption that GLOBALS is read-only and can defeat application-level security checks, so any affected PHP application relying on register_globals is exposed.

7.5 CVSS 2.0 High EPSS 66% · top 0.8%
7.5CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
66References
16 Jun 2026Last modified by NVD

Description

The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote variable overwrite with high EPSS and broad legacy PHP exposure, though exploitation depends on register_globals being enabled.

What it is

PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, lets a remote attacker overwrite the GLOBALS array through a multipart/form-data POST request containing a fileupload field named GLOBALS. This breaks the assumption that GLOBALS is read-only and can defeat application-level security checks, so any affected PHP application relying on register_globals is exposed.

Impact

An attacker can inject or overwrite global variables and the GLOBALS array, potentially bypassing authentication, authorization or input-validation logic in the hosted application. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

Reachable over the network via an unauthenticated HTTP POST with multipart/form-data to any PHP script that processes file uploads. No credentials or user interaction are required, but the flaw only applies when register_globals is enabled.

Exploitation

Not listed in CISA KEV and no ransomware usage documented. EPSS is high (0.655, 99.2nd percentile), and references include vendor patch and advisory tags, indicating public technical detail and fixes rather than confirmed in-the-wild exploitation.

What to do

  • Upgrade PHP to 4.4.1 or 5.0.6 (or later) per the vendor release notes and distribution advisories.
  • Disable register_globals in php.ini; this configuration is the precondition for the flaw.
  • Apply the relevant OS vendor errata (Red Hat, Fedora Legacy, Gentoo, Mandriva, Novell, OpenPKG, Avaya) if upgrading PHP directly is not possible.
  • Audit application code for reliance on register_globals and replace it with explicit superglobal access.
  • Restrict or disable file upload handling on legacy PHP deployments that cannot be patched.

Detection

  • Search web logs for multipart/form-data POST requests containing a fileupload field named GLOBALS.
  • Monitor for unexpected changes to global variables or authentication state in PHP application logs.
  • Inventory PHP versions and php.ini settings to find hosts running 4.x <= 4.4.0 or 5.x <= 5.0.5 with register_globals enabled.
  • Review IDS/WAF rules for GLOBALS parameter injection in upload requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522
http://rhn.redhat.com/errata/RHSA-2006-0549.html
http://secunia.com/advisories/17371 PatchVendor Advisory
http://secunia.com/advisories/17490
http://secunia.com/advisories/17510
http://secunia.com/advisories/17531
http://secunia.com/advisories/17557
http://secunia.com/advisories/17559
http://secunia.com/advisories/18054
http://secunia.com/advisories/18198
http://secunia.com/advisories/18669
http://secunia.com/advisories/21252
http://secunia.com/advisories/22691
http://securityreason.com/securityalert/132
http://securitytracker.com/id?1015129
http://support.avaya.com/elmodocs2/security/ASA-2006-037.htm
http://www.fedoralegacy.org/updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.html
http://www.gentoo.org/security/en/glsa/glsa-200511-08.xml
http://www.hardened-php.net/advisory_202005.79.html Vendor Advisory
http://www.hardened-php.net/globals-problem
http://www.mandriva.com/security/advisories?name=MDKSA-2005:213
http://www.novell.com/linux/security/advisories/2005_27_sr.html
http://www.openpkg.org/security/OpenPKG-SA-2005.027-php.html
http://www.php.net/release_4_4_1.php Patch
http://www.redhat.com/support/errata/RHSA-2005-831.html
http://www.redhat.com/support/errata/RHSA-2005-838.html
http://www.securityfocus.com/archive/1/415290/30/0/threaded
http://www.securityfocus.com/archive/1/419504/100/0/threaded
http://www.securityfocus.com/bid/15250 Patch
http://www.vupen.com/english/advisories/2005/2254
http://www.vupen.com/english/advisories/2006/4320
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10537
https://www.ubuntu.com/usn/usn-232-1/
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522
http://rhn.redhat.com/errata/RHSA-2006-0549.html
http://secunia.com/advisories/17371 PatchVendor Advisory
http://secunia.com/advisories/17490
http://secunia.com/advisories/17510
http://secunia.com/advisories/17531
http://secunia.com/advisories/17557

Track CVE-2005-3390 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed10.0CVE-2015-0235glibc gethostbyname heap buffer overflow (GHOST)CVE-2015-0235 is a heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2 and other 2.x versions before 2.18. It is reach…EPSS 95%analysed10.0CVE-2012-2688Php vulnerabilityUnspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown im…EPSS 10%10.0CVE-2012-2376Php memory buffer overflow vulnerabilityBuffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted …EPSS 20%10.0CVE-2011-3268Php memory buffer overflow vulnerabilityBuffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, …EPSS 5.7%10.0CVE-2009-4143Php vulnerabilityPHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the S…EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2005-3390), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.