Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-4142

Опубликовано: 06 окт. 2009
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=548516php: htmlspecialchars() insufficient checking of input for multi-byte encodings

EPSS

Процентиль: 95%
0.17366
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

nvd
больше 15 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

debian
больше 15 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly h ...

github
больше 3 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

oracle-oval
больше 15 лет назад

ELSA-2010-0040: php security update (MODERATE)

EPSS

Процентиль: 95%
0.17366
Средний

4.3 Medium

CVSS2