AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-3390

HIGH · CVSS 7.5 EPSS 65.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-11-01 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. Its EPSS score suggests a 65.5% probability of exploitation in the next 30 days. It may be remotely exploitable.

CVE
CVE-2005-3390
Severity
HIGH
CVSS
7.5
EPSS
65.51%

Original NVD Description

The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.