ZeroHour

CVE-2000-0967

PoC
CVSS 2.0
10.0 high
EPSS
Published
()
Modified
Description

PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

Vendors
php
Products
php
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C

In the news

No ingested article mentions this CVE yet.