Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-5016

Опубликовано: 12 нояб. 2010
Источник: debian
EPSS Низкий

Описание

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php5fixed5.3.3-4package
php5fixed5.2.6.dfsg.1-1+lenny10lennypackage
php5fixed5.3.3-7+squeeze1squeezepackage

Примечания

  • Also fixed by debian/patches/CVE-2010-3870.patch

EPSS

Процентиль: 86%
0.02982
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

redhat
больше 15 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

nvd
больше 14 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

github
около 3 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

oracle-oval
больше 14 лет назад

ELSA-2011-0195: php security update (MODERATE)

EPSS

Процентиль: 86%
0.02982
Низкий