PT-2020-6652 · Php · Php
Vasyl Kaigorodov
·
Published
2020-02-19
·
Updated
2024-06-15
·
CVE-2014-3622
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PHP versions 5.6.x through 5.6.0
Description
The issue is related to a use-after-free vulnerability in the
add post var function of the Posthandler component. This vulnerability can be exploited by remote attackers to execute arbitrary PHP code by leveraging a third-party filter extension that accesses a certain ksep value.Recommendations
For PHP versions 5.6.x through 5.6.0, update to version 5.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to third-party filter extensions that may access the
ksep value until a patch is applied.Exploit
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php