{"api_version":"1","generated_at":"2026-07-24T21:43:20+00:00","cve":"CVE-2004-0958","urls":{"html":"https://cve.report/CVE-2004-0958","api":"https://cve.report/api/cve/CVE-2004-0958.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-0958","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-0958"},"summary":{"title":"CVE-2004-0958","description":"php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-11-03 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17393","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17393","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2004-687.html","name":"http://www.redhat.com/support/errata/RHSA-2004-687.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10863","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10863","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.fedora.us/show_bug.cgi?id=2344","name":"https://bugzilla.fedora.us/show_bug.cgi?id=2344","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0053.html","name":"http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0053.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - VulnWatch - #0053 - [VulnWatch] PHP Vulnerability N. 1","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/12560/","name":"http://secunia.com/advisories/12560/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - PHP Memory Leak and Arbitrary File Location Upload Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1011279","name":"http://securitytracker.com/id?1011279","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - PHP Array Parsing Error in php_variables May Disclose Memory Contents via phpinfo()","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=109527531130492&w=2","name":"http://marc.info/?l=bugtraq&m=109527531130492&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'PHP Vulnerability N. 1' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-0958","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0958","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"958","vulnerable":"1","versionEndIncluding":"5.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:31:48.274Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040915 [VulnWatch] PHP Vulnerability N. 1","tags":["mailing-list","x_refsource_VULNWATCH","x_transferred"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0053.html"},{"name":"20040915 PHP Vulnerability N. 1","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=109527531130492&w=2"},{"name":"12560","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12560/"},{"name":"1011279","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1011279"},{"name":"FLSA:2344","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://bugzilla.fedora.us/show_bug.cgi?id=2344"},{"name":"php-phpinfo-disclose-memory(17393)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17393"},{"name":"oval:org.mitre.oval:def:10863","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10863"},{"name":"RHSA-2004:687","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2004-687.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-09-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-10T00:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040915 [VulnWatch] PHP Vulnerability N. 1","tags":["mailing-list","x_refsource_VULNWATCH"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0053.html"},{"name":"20040915 PHP Vulnerability N. 1","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=109527531130492&w=2"},{"name":"12560","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12560/"},{"name":"1011279","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1011279"},{"name":"FLSA:2344","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://bugzilla.fedora.us/show_bug.cgi?id=2344"},{"name":"php-phpinfo-disclose-memory(17393)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17393"},{"name":"oval:org.mitre.oval:def:10863","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10863"},{"name":"RHSA-2004:687","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2004-687.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-0958","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040915 [VulnWatch] PHP Vulnerability N. 1","refsource":"VULNWATCH","url":"http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0053.html"},{"name":"20040915 PHP Vulnerability N. 1","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=109527531130492&w=2"},{"name":"12560","refsource":"SECUNIA","url":"http://secunia.com/advisories/12560/"},{"name":"1011279","refsource":"SECTRACK","url":"http://securitytracker.com/id?1011279"},{"name":"FLSA:2344","refsource":"FEDORA","url":"https://bugzilla.fedora.us/show_bug.cgi?id=2344"},{"name":"php-phpinfo-disclose-memory(17393)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17393"},{"name":"oval:org.mitre.oval:def:10863","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10863"},{"name":"RHSA-2004:687","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2004-687.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-0958","datePublished":"2004-10-16T04:00:00.000Z","dateReserved":"2004-10-13T00:00:00.000Z","dateUpdated":"2024-08-08T00:31:48.274Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-11-03 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionEndIncluding":"5.0.2","matchCriteriaId":"EAE1CCE0-7682-40EA-A858-DD09A3E32AF7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"958","Ordinal":"1","Title":"CVE-2004-0958","CVE":"CVE-2004-0958","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"958","Ordinal":"1","NoteData":"php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.","Type":"Description","Title":"CVE-2004-0958"},{"CveYear":"2004","CveId":"958","Ordinal":"2","NoteData":"2004-10-16","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"958","Ordinal":"3","NoteData":"2017-10-09","Type":"Other","Title":"Modified"}]}}}