Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jx2x-3hjr-6vp8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

EPSS

Процентиль: 94%
0.06797
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

CVSS3: 9.8
nvd
около 7 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

CVSS3: 9.8
debian
около 7 лет назад

A type confusion vulnerability in the merge_param() function of php_ht ...

EPSS

Процентиль: 94%
0.06797
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-704