Описание
The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplace function.
Ссылки
- Mailing ListThird Party Advisory
- ExploitIssue TrackingVendor Advisory
- Mailing ListThird Party Advisory
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
7.3 High
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplace function.
The php_str_replace_in_subject function in ext/standard/string.c in PH ...
The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplace function.
Уязвимость интерпретатора PHP, позволяющая нарушителю выполнить произвольный код
EPSS
7.3 High
CVSS3
7.5 High
CVSS2