Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-5016

Опубликовано: 12 нояб. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

РелизСтатусПримечание
dapper

released

5.1.2-1ubuntu3.20
devel

not-affected

hardy

released

5.2.4-2ubuntu5.13
karmic

released

5.2.10.dfsg.1-2ubuntu6.6
lucid

not-affected

maverick

not-affected

upstream

released

5.2.11

Показывать по

EPSS

Процентиль: 86%
0.02982
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

nvd
больше 14 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

debian
больше 14 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in P ...

github
около 3 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

oracle-oval
больше 14 лет назад

ELSA-2011-0195: php security update (MODERATE)

EPSS

Процентиль: 86%
0.02982
Низкий

6.8 Medium

CVSS2

Уязвимость CVE-2009-5016