Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4142

Опубликовано: 21 дек. 2009
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4.3

Описание

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

РелизСтатусПримечание
dapper

released

5.1.2-1ubuntu3.18
devel

not-affected

5.2.12.dfsg.1-2ubuntu1
hardy

released

5.2.4-2ubuntu5.10
intrepid

released

5.2.6-2ubuntu4.6
jaunty

released

5.2.6.dfsg.1-3ubuntu4.5
karmic

released

5.2.10.dfsg.1-2ubuntu6.4
upstream

released

5.2.12

Показывать по

EPSS

Процентиль: 94%
0.13292
Средний

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

nvd
больше 15 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

debian
больше 15 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly h ...

github
около 3 лет назад

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

oracle-oval
больше 15 лет назад

ELSA-2010-0040: php security update (MODERATE)

EPSS

Процентиль: 94%
0.13292
Средний

4.3 Medium

CVSS2