Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

ubuntu логотип

CVE-2024-4577

больше 2 лет назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS3: 9.8
EPSS: Критический
redhat логотип

CVE-2024-4577

больше 2 лет назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2024-4577

больше 2 лет назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS3: 9.8
EPSS: Критический
msrc логотип

CVE-2024-4577

8 месяцев назад

Argument Injection in PHP-CGI

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2024-4577

больше 2 лет назад

In PHP versions8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before ...

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-vxpp-6299-mxw3

больше 2 лет назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3qgc-jrrr-25jv

около 2 лет назад

PHP RCE: A Bypass of CVE-2012-1823, Argument Injection in PHP-CGI

EPSS: Критический
fstec логотип

BDU:2024-04432

больше 2 лет назад

Уязвимость интерпретатора языка программирования PHP, существующая из-за непринятия мер по нейтрализации специальных элементов, используемых в команде операционной системмы, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
EPSS: Критический
altlinux логотип

ALT-PU-2024-8861

больше 2 лет назад

ALT-PU-2024-8861: package `php8.3` update to version 8.3.8-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-8859

больше 2 лет назад

ALT-PU-2024-8859: package `php8.2` update to version 8.2.20-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-8853

больше 2 лет назад

ALT-PU-2024-8853: package `php8.1` update to version 8.1.29-alt1

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20240816-16

около 2 лет назад

Множественные уязвимости php

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20240816-11

около 2 лет назад

Множественные уязвимости php

CVSS3: 8.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-9193

больше 2 лет назад

ALT-PU-2024-9193: package `php8.2` update to version 8.2.20-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-9191

больше 2 лет назад

ALT-PU-2024-9191: package `php8.1` update to version 8.1.29-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-18046

больше 2 лет назад

ALT-PU-2024-18046: package `php8.1-soap` update to version 8.1.29-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-18036

больше 2 лет назад

ALT-PU-2024-18036: package `php8.2-soap` update to version 8.2.20-alt1

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-4577

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS3: 9.8
100%
Критический
больше 2 лет назад
redhat логотип
CVE-2024-4577

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS3: 9.8
100%
Критический
больше 2 лет назад
nvd логотип
CVE-2024-4577

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS3: 9.8
100%
Критический
больше 2 лет назад
msrc логотип
CVE-2024-4577

Argument Injection in PHP-CGI

CVSS3: 9.8
100%
Критический
8 месяцев назад
debian логотип
CVE-2024-4577

In PHP versions8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before ...

CVSS3: 9.8
100%
Критический
больше 2 лет назад
github логотип
GHSA-vxpp-6299-mxw3

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS3: 9.8
100%
Критический
больше 2 лет назад
github логотип
GHSA-3qgc-jrrr-25jv

PHP RCE: A Bypass of CVE-2012-1823, Argument Injection in PHP-CGI

100%
Критический
около 2 лет назад
fstec логотип
BDU:2024-04432

Уязвимость интерпретатора языка программирования PHP, существующая из-за непринятия мер по нейтрализации специальных элементов, используемых в команде операционной системмы, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
100%
Критический
больше 2 лет назад
altlinux логотип
ALT-PU-2024-8861

ALT-PU-2024-8861: package `php8.3` update to version 8.3.8-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-8859

ALT-PU-2024-8859: package `php8.2` update to version 8.2.20-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-8853

ALT-PU-2024-8853: package `php8.1` update to version 8.1.29-alt1

CVSS3: 9.8
больше 2 лет назад
redos логотип
ROS-20240816-16

Множественные уязвимости php

CVSS3: 8.8
около 2 лет назад
redos логотип
ROS-20240816-11

Множественные уязвимости php

CVSS3: 8.8
около 2 лет назад
altlinux логотип
ALT-PU-2024-9193

ALT-PU-2024-9193: package `php8.2` update to version 8.2.20-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-9191

ALT-PU-2024-9191: package `php8.1` update to version 8.1.29-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-18046

ALT-PU-2024-18046: package `php8.1-soap` update to version 8.1.29-alt1

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2024-18036

ALT-PU-2024-18036: package `php8.2-soap` update to version 8.2.20-alt1

CVSS3: 9.8
больше 2 лет назад

Уязвимостей на страницу