Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Takayuki Uchiyama

#22568of 53,633
10Total CVSS
Vulnerabilities · 1
PT-2016-2022
10
2015-07-05
Php · Php · CVE-2015-4642
**Name of the Vulnerable Software and Affected Versions** PHP versions prior to 5.4.42 PHP versions 5.5.x prior to 5.5.26 PHP versions 5.6.x prior to 5.6.10 **Description** The issue allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function. This is due to the escapeshellarg function not properly neutralizing special elements used in the operating system command. **Recommendations** For PHP versions prior to 5.4.42, update to version 5.4.42 or later. For PHP versions 5.5.x prior to 5.5.26, update to version 5.5.26 or later. For PHP versions 5.6.x prior to 5.6.10, update to version 5.6.10 or later.