Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-7398

Опубликовано: 06 сент. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:php:ext-http:*:*:*:*:*:*:*:*
Версия до 2.5.6 (включая)
cpe:2.3:a:php:ext-http:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.1 (включая)
cpe:2.3:a:php:ext-http:2.6.0:-:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:2.6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:2.6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:2.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:3.1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:3.1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:3.1.0:rc1:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05723
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

CVSS3: 9.8
debian
больше 6 лет назад

A type confusion vulnerability in the merge_param() function of php_ht ...

CVSS3: 9.8
github
больше 3 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

EPSS

Процентиль: 90%
0.05723
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-704