ZeroHour

CVE-2017-5677

CVSS 3.0
9.8 critical
EPSS
5%p91
Published
()
Modified
Description

PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.

Vendors
pear
Products
html ajax
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.