Количество 16
Количество 16
CVE-2024-5585
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
CVE-2024-5585
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
CVE-2024-5585
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
CVE-2024-5585
Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)
CVE-2024-5585
In PHP versions8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before ...
GHSA-9fcc-425m-g385
bypass CVE-2024-1874
BDU:2024-05512
Уязвимость функции proc_open() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольные команды
ALT-PU-2024-8861
ALT-PU-2024-8861: package `php8.3` update to version 8.3.8-alt1
ALT-PU-2024-8859
ALT-PU-2024-8859: package `php8.2` update to version 8.2.20-alt1
ALT-PU-2024-8853
ALT-PU-2024-8853: package `php8.1` update to version 8.1.29-alt1
ROS-20240816-16
Множественные уязвимости php
ROS-20240816-11
Множественные уязвимости php
ALT-PU-2024-9193
ALT-PU-2024-9193: package `php8.2` update to version 8.2.20-alt1
ALT-PU-2024-9191
ALT-PU-2024-9191: package `php8.1` update to version 8.1.29-alt1
ALT-PU-2024-18046
ALT-PU-2024-18046: package `php8.1-soap` update to version 8.1.29-alt1
ALT-PU-2024-18036
ALT-PU-2024-18036: package `php8.2-soap` update to version 8.2.20-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-5585 In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell. | CVSS3: 7.7 | 29% Средний | больше 2 лет назад | |
CVE-2024-5585 In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell. | CVSS3: 8.8 | 29% Средний | больше 2 лет назад | |
CVE-2024-5585 In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell. | CVSS3: 7.7 | 29% Средний | больше 2 лет назад | |
CVE-2024-5585 Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix) | CVSS3: 8.8 | 29% Средний | больше 2 лет назад | |
CVE-2024-5585 In PHP versions8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before ... | CVSS3: 7.7 | 29% Средний | больше 2 лет назад | |
GHSA-9fcc-425m-g385 bypass CVE-2024-1874 | CVSS3: 7.7 | 29% Средний | больше 2 лет назад | |
BDU:2024-05512 Уязвимость функции proc_open() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольные команды | CVSS3: 8.8 | 29% Средний | больше 2 лет назад | |
ALT-PU-2024-8861 ALT-PU-2024-8861: package `php8.3` update to version 8.3.8-alt1 | CVSS3: 9.8 | больше 2 лет назад | ||
ALT-PU-2024-8859 ALT-PU-2024-8859: package `php8.2` update to version 8.2.20-alt1 | CVSS3: 9.8 | больше 2 лет назад | ||
ALT-PU-2024-8853 ALT-PU-2024-8853: package `php8.1` update to version 8.1.29-alt1 | CVSS3: 9.8 | больше 2 лет назад | ||
ROS-20240816-16 Множественные уязвимости php | CVSS3: 8.8 | около 2 лет назад | ||
ROS-20240816-11 Множественные уязвимости php | CVSS3: 8.8 | около 2 лет назад | ||
ALT-PU-2024-9193 ALT-PU-2024-9193: package `php8.2` update to version 8.2.20-alt1 | CVSS3: 9.8 | больше 2 лет назад | ||
ALT-PU-2024-9191 ALT-PU-2024-9191: package `php8.1` update to version 8.1.29-alt1 | CVSS3: 9.8 | больше 2 лет назад | ||
ALT-PU-2024-18046 ALT-PU-2024-18046: package `php8.1-soap` update to version 8.1.29-alt1 | CVSS3: 9.8 | больше 2 лет назад | ||
ALT-PU-2024-18036 ALT-PU-2024-18036: package `php8.2-soap` update to version 8.2.20-alt1 | CVSS3: 9.8 | больше 2 лет назад |
Уязвимостей на страницу