ZeroHour

CVE-2016-7398

PoC ×2
CVSS 3.1
9.8 critical
EPSS
7%p94
Published
()
Modified
Description

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

Vendors
php
Products
ext-http
Weakness
CWE-704
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.