Количество 17
Количество 17
GHSA-pc52-254m-w9w7
Command injection via array-ish $command parameter of proc_open even if bypass_shell option enabled on Windows
CVE-2024-1874
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
CVE-2024-1874
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
CVE-2024-1874
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
CVE-2024-1874
Command injection via array-ish $command parameter of proc_open()
CVE-2024-1874
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before ...
BDU:2025-11445
Уязвимость функции proc_open() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольные команды
ALT-PU-2024-18408
ALT-PU-2024-18408: package `php8.2-soap` update to version 8.2.18-alt1
ALT-PU-2024-18310
ALT-PU-2024-18310: package `php8.1-soap` update to version 8.1.28-alt1
ALT-PU-2024-18045
ALT-PU-2024-18045: package `php8.1-soap` update to version 8.1.28-alt1
ALT-PU-2024-18035
ALT-PU-2024-18035: package `php8.2-soap` update to version 8.2.18-alt1
ALT-PU-2024-6566
ALT-PU-2024-6566: package `php8.1` update to version 8.1.28-alt1
ALT-PU-2024-6501
ALT-PU-2024-6501: package `php8.2` update to version 8.2.18-alt1
ALT-PU-2024-6496
ALT-PU-2024-6496: package `php8.1` update to version 8.1.28-alt1
ALT-PU-2024-6444
ALT-PU-2024-6444: package `php8.2` update to version 8.2.18-alt1
ALT-PU-2024-18156
ALT-PU-2024-18156: package `php8.3-soap` update to version 8.3.6-alt1
ALT-PU-2024-6442
ALT-PU-2024-6442: package `php8.3` update to version 8.3.6-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-pc52-254m-w9w7 Command injection via array-ish $command parameter of proc_open even if bypass_shell option enabled on Windows | CVSS3: 9.4 | 33% Средний | больше 2 лет назад | |
CVE-2024-1874 In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell. | CVSS3: 9.4 | 33% Средний | больше 2 лет назад | |
CVE-2024-1874 In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell. | 33% Средний | больше 2 лет назад | ||
CVE-2024-1874 In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell. | CVSS3: 9.4 | 33% Средний | больше 2 лет назад | |
CVE-2024-1874 Command injection via array-ish $command parameter of proc_open() | CVSS3: 9.4 | 33% Средний | 8 месяцев назад | |
CVE-2024-1874 In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before ... | CVSS3: 9.4 | 33% Средний | больше 2 лет назад | |
BDU:2025-11445 Уязвимость функции proc_open() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольные команды | CVSS3: 9.4 | 33% Средний | больше 2 лет назад | |
ALT-PU-2024-18408 ALT-PU-2024-18408: package `php8.2-soap` update to version 8.2.18-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-18310 ALT-PU-2024-18310: package `php8.1-soap` update to version 8.1.28-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-18045 ALT-PU-2024-18045: package `php8.1-soap` update to version 8.1.28-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-18035 ALT-PU-2024-18035: package `php8.2-soap` update to version 8.2.18-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-6566 ALT-PU-2024-6566: package `php8.1` update to version 8.1.28-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-6501 ALT-PU-2024-6501: package `php8.2` update to version 8.2.18-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-6496 ALT-PU-2024-6496: package `php8.1` update to version 8.1.28-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-6444 ALT-PU-2024-6444: package `php8.2` update to version 8.2.18-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-18156 ALT-PU-2024-18156: package `php8.3-soap` update to version 8.3.6-alt1 | CVSS3: 9.4 | больше 2 лет назад | ||
ALT-PU-2024-6442 ALT-PU-2024-6442: package `php8.3` update to version 8.3.6-alt1 | CVSS3: 9.4 | больше 2 лет назад |
Уязвимостей на страницу