Описание
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.
Уязвимые конфигурации
Конфигурация 1Версия до 2.4.1 (включая)
cpe:2.3:a:facebook:hiphop_virtual_machine:*:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00697
Низкий
7.5 High
CVSS2
Дефекты
CWE-94
Связанные уязвимости
github
около 3 лет назад
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.
EPSS
Процентиль: 71%
0.00697
Низкий
7.5 High
CVSS2
Дефекты
CWE-94