Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6175

Опубликовано: 07 фев. 2017
Источник: debian

Описание

Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-gettextfixed1.0.12-1package
php-gettextno-dsabusterpackage
php-gettextno-dsastretchpackage
php-gettextno-dsajessiepackage
php-gettextno-dsawheezypackage

Примечания

  • https://bugs.launchpad.net/php-gettext/+bug/1606184

  • https://kmkz-web-blog.blogspot.cz/2016/07/advisory-cve-2016-6175.html

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.

CVSS3: 9.8
nvd
около 9 лет назад

Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.

CVSS3: 9.8
github
больше 3 лет назад

Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.