Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9m5-q9x5-6877

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

Ссылки

EPSS

Процентиль: 98%
0.51567
Средний

9.8 Critical

CVSS3

Дефекты

CWE-131

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 17 лет назад

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

redhat
около 17 лет назад

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

CVSS3: 9.8
nvd
около 17 лет назад

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

CVSS3: 9.8
debian
около 17 лет назад

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5. ...

EPSS

Процентиль: 98%
0.51567
Средний

9.8 Critical

CVSS3

Дефекты

CWE-131