Логотип exploitDog
bind:CVE-2020-7066
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-7066

Количество 13

Количество 13

ubuntu логотип

CVE-2020-7066

почти 6 лет назад

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-7066

почти 6 лет назад

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-7066

почти 6 лет назад

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-7066

почти 6 лет назад

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g2jm-56j8-g3cg

больше 3 лет назад

In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.34, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2020-02387

почти 6 лет назад

Уязвимость реализации функции get_headers() интерпретатора языка программирования PHP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0642-1

больше 5 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1199-1

больше 5 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1714-1

больше 5 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1546-1

больше 5 лет назад

Security update for php72

EPSS: Низкий
rocky логотип

RLSA-2020:3662

больше 5 лет назад

Moderate: php:7.3 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3662

больше 5 лет назад

ELSA-2020-3662: php:7.3 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4067-1

около 3 лет назад

Security update for php7

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-7066

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 5.3
2%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-7066

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 4.3
2%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-7066

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 5.3
2%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-7066

In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below ...

CVSS3: 5.3
2%
Низкий
почти 6 лет назад
github логотип
GHSA-g2jm-56j8-g3cg

In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.34, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

CVSS3: 4.3
2%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-02387

Уязвимость реализации функции get_headers() интерпретатора языка программирования PHP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
2%
Низкий
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0642-1

Security update for php7

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1199-1

Security update for php7

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1714-1

Security update for php5

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1546-1

Security update for php72

больше 5 лет назад
rocky логотип
RLSA-2020:3662

Moderate: php:7.3 security, bug fix, and enhancement update

больше 5 лет назад
oracle-oval логотип
ELSA-2020-3662

ELSA-2020-3662: php:7.3 security, bug fix, and enhancement update (MODERATE)

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2022:4067-1

Security update for php7

около 3 лет назад

Уязвимостей на страницу