Логотип exploitDog
bind:CVE-2020-7066
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-7066

Количество 13

Количество 13

ubuntu логотип

CVE-2020-7066

около 5 лет назад

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-7066

около 5 лет назад

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-7066

около 5 лет назад

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-7066

около 5 лет назад

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g2jm-56j8-g3cg

около 3 лет назад

In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.34, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2020-02387

больше 5 лет назад

Уязвимость реализации функции get_headers() интерпретатора языка программирования PHP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0642-1

около 5 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1199-1

около 5 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1714-1

почти 5 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1546-1

около 5 лет назад

Security update for php72

EPSS: Низкий
rocky логотип

RLSA-2020:3662

почти 5 лет назад

Moderate: php:7.3 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3662

почти 5 лет назад

ELSA-2020-3662: php:7.3 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4067-1

больше 2 лет назад

Security update for php7

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-7066

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 5.3
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-7066

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 4.3
2%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-7066

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 5.3
2%
Низкий
около 5 лет назад
debian логотип
CVE-2020-7066

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below ...

CVSS3: 5.3
2%
Низкий
около 5 лет назад
github логотип
GHSA-g2jm-56j8-g3cg

In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.34, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 4.3
2%
Низкий
около 3 лет назад
fstec логотип
BDU:2020-02387

Уязвимость реализации функции get_headers() интерпретатора языка программирования PHP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
2%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0642-1

Security update for php7

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1199-1

Security update for php7

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1714-1

Security update for php5

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1546-1

Security update for php72

около 5 лет назад
rocky логотип
RLSA-2020:3662

Moderate: php:7.3 security, bug fix, and enhancement update

почти 5 лет назад
oracle-oval логотип
ELSA-2020-3662

ELSA-2020-3662: php:7.3 security, bug fix, and enhancement update (MODERATE)

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2022:4067-1

Security update for php7

больше 2 лет назад

Уязвимостей на страницу