We found results for “”
WS-2018-0212
Good to know:
Date: October 11, 2018
PHAR archives may be crafted such that their stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Deserialization of Untrusted Data
CWE-502Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |