CVE-2000-0967
PoC —CVSS 2.0
10.0 high
EPSS
—
Published
()
Modified
Description
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
- Vendors
- php
- Products
- php
- Vector
- AV:N/AC:L/Au:N/C:C/I:C/A:C
In the news0 stories
No ingested article mentions this CVE yet.