Описание
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was deprecated in early 2020.
Ссылки
- Product
- Broken Link
- Product
- Product
- Broken Link
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.3 (включая)
cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02497
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 9.8
debian
почти 3 года назад
An issue found in Zend Framework v.3.1.3 and before allow a remote att ...
CVSS3: 9.8
github
почти 3 года назад
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.
EPSS
Процентиль: 85%
0.02497
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-502