Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2024-5585

больше 2 лет назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVSS3: 7.7
EPSS: Средний
redhat логотип

CVE-2024-5585

больше 2 лет назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2024-5585

больше 2 лет назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVSS3: 7.7
EPSS: Средний
msrc логотип

CVE-2024-5585

больше 2 лет назад

Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2024-5585

больше 2 лет назад

In PHP versions8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before ...

CVSS3: 7.7
EPSS: Средний
github логотип

GHSA-9fcc-425m-g385

больше 2 лет назад

bypass CVE-2024-1874

CVSS3: 7.7
EPSS: Средний
fstec логотип

BDU:2024-05512

больше 2 лет назад

Уязвимость функции proc_open() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.8
EPSS: Средний
altlinux логотип

ALT-PU-2024-8861

больше 2 лет назад

ALT-PU-2024-8861: package `php8.3` update to version 8.3.8-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-8859

больше 2 лет назад

ALT-PU-2024-8859: package `php8.2` update to version 8.2.20-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-8853

больше 2 лет назад

ALT-PU-2024-8853: package `php8.1` update to version 8.1.29-alt1

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20240816-16

около 2 лет назад

Множественные уязвимости php

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20240816-11

около 2 лет назад

Множественные уязвимости php

CVSS3: 8.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-9193

больше 2 лет назад

ALT-PU-2024-9193: package `php8.2` update to version 8.2.20-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-9191

больше 2 лет назад

ALT-PU-2024-9191: package `php8.1` update to version 8.1.29-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-18046

больше 2 лет назад

ALT-PU-2024-18046: package `php8.1-soap` update to version 8.1.29-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-18036

больше 2 лет назад

ALT-PU-2024-18036: package `php8.2-soap` update to version 8.2.20-alt1

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-5585

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVSS3: 7.7
29%
Средний
больше 2 лет назад
redhat логотип
CVE-2024-5585

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVSS3: 8.8
29%
Средний
больше 2 лет назад
nvd логотип
CVE-2024-5585

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVSS3: 7.7
29%
Средний
больше 2 лет назад
msrc логотип
CVE-2024-5585

Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)

CVSS3: 8.8
29%
Средний
больше 2 лет назад
debian логотип
CVE-2024-5585

In PHP versions8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before ...

CVSS3: 7.7
29%
Средний
больше 2 лет назад
github логотип
GHSA-9fcc-425m-g385

bypass CVE-2024-1874

CVSS3: 7.7
29%
Средний
больше 2 лет назад
fstec логотип
BDU:2024-05512

Уязвимость функции proc_open() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.8
29%
Средний
больше 2 лет назад
altlinux логотип
ALT-PU-2024-8861

ALT-PU-2024-8861: package `php8.3` update to version 8.3.8-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-8859

ALT-PU-2024-8859: package `php8.2` update to version 8.2.20-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-8853

ALT-PU-2024-8853: package `php8.1` update to version 8.1.29-alt1

CVSS3: 9.8
больше 2 лет назад
redos логотип
ROS-20240816-16

Множественные уязвимости php

CVSS3: 8.8
около 2 лет назад
redos логотип
ROS-20240816-11

Множественные уязвимости php

CVSS3: 8.8
около 2 лет назад
altlinux логотип
ALT-PU-2024-9193

ALT-PU-2024-9193: package `php8.2` update to version 8.2.20-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-9191

ALT-PU-2024-9191: package `php8.1` update to version 8.1.29-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-18046

ALT-PU-2024-18046: package `php8.1-soap` update to version 8.1.29-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-18036

ALT-PU-2024-18036: package `php8.2-soap` update to version 8.2.20-alt1

CVSS3: 9.8
больше 2 лет назад

Уязвимостей на страницу