Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-5677

Опубликовано: 06 фев. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pear:html_ajax:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.3.4:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.4.0:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.4.1:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.5.0:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.5.1:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.5.2:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.5.3:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.5.4:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.5.5:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.5.6:*:*:*:*:*:*:*
cpe:2.3:a:pear:html_ajax:0.5.7:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.04016
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.

EPSS

Процентиль: 88%
0.04016
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo