Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3870

Опубликовано: 27 сент. 2009
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5php53Affected
Red Hat Enterprise Linux 4phpFixedRHSA-2010:091929.11.2010
Red Hat Enterprise Linux 5phpFixedRHSA-2010:091929.11.2010
Red Hat Enterprise Linux 6phpFixedRHSA-2011:019503.02.2011

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=649056php: XSS mitigation bypass via utf8_decode()

EPSS

Процентиль: 66%
0.00535
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

nvd
больше 14 лет назад

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

debian
больше 14 лет назад

The utf8_decode function in PHP before 5.3.4 does not properly handle ...

github
около 3 лет назад

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

CVSS3: 7.3
fstec
больше 14 лет назад

Уязвимость функции utf8_decode интерпретатора языка программирования PHP, позволяющая нарушителю провести XSS-атаки

EPSS

Процентиль: 66%
0.00535
Низкий

4.3 Medium

CVSS2