Логотип exploitDog
bind:"CVE-2024-8927"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-8927"

Количество 19

Количество 19

ubuntu логотип

CVE-2024-8927

9 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-8927

9 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-8927

9 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-8927

7 месяцев назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-8927

9 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-94p6-54jq-9mwp

9 месяцев назад

cgi.force_redirect configuration is bypassable due to the environment variable collision

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-07679

9 месяцев назад

Уязвимость сценария cgi.force_redirect интерпретатора языка программирования PHP, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3733-1

8 месяцев назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3732-1

8 месяцев назад

Security update for php74

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3729-1

8 месяцев назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3664-1

8 месяцев назад

Security update for php8

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10951

6 месяцев назад

ELSA-2024-10951: php:8.2 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10950

6 месяцев назад

ELSA-2024-10950: php:8.1 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10949

6 месяцев назад

ELSA-2024-10949: php:8.2 security update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20241015-15

8 месяцев назад

Множественные уязвимости php

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20241015-14

8 месяцев назад

Множественные уязвимости php

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20241015-11

8 месяцев назад

Множественные уязвимости php

CVSS3: 9.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-7315

около 1 месяца назад

ELSA-2025-7315: php security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10952

6 месяцев назад

ELSA-2024-10952: php:7.4 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-8927

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
redhat логотип
CVE-2024-8927

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2024-8927

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
msrc логотип
CVSS3: 7.5
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-8927

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before ...

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-94p6-54jq-9mwp

cgi.force_redirect configuration is bypassable due to the environment variable collision

CVSS3: 5.3
0%
Низкий
9 месяцев назад
fstec логотип
BDU:2024-07679

Уязвимость сценария cgi.force_redirect интерпретатора языка программирования PHP, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 9.8
0%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3733-1

Security update for php7

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3732-1

Security update for php74

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3729-1

Security update for php8

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3664-1

Security update for php8

8 месяцев назад
oracle-oval логотип
ELSA-2024-10951

ELSA-2024-10951: php:8.2 security update (MODERATE)

6 месяцев назад
oracle-oval логотип
ELSA-2024-10950

ELSA-2024-10950: php:8.1 security update (MODERATE)

6 месяцев назад
oracle-oval логотип
ELSA-2024-10949

ELSA-2024-10949: php:8.2 security update (MODERATE)

6 месяцев назад
redos логотип
ROS-20241015-15

Множественные уязвимости php

CVSS3: 9.8
8 месяцев назад
redos логотип
ROS-20241015-14

Множественные уязвимости php

CVSS3: 9.8
8 месяцев назад
redos логотип
ROS-20241015-11

Множественные уязвимости php

CVSS3: 9.8
8 месяцев назад
oracle-oval логотип
ELSA-2025-7315

ELSA-2025-7315: php security update (MODERATE)

около 1 месяца назад
oracle-oval логотип
ELSA-2024-10952

ELSA-2024-10952: php:7.4 security update (MODERATE)

6 месяцев назад

Уязвимостей на страницу