Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-2950

Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the phar_stream_flush function, leading to errors in the php_stream_wrapper_log_error function. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2094.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.6%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2010-2950
  • Php » Php » Version: 5.3.0
    cpe:2.3:a:php:php:5.3.0
  • Php » Php » Version: 5.3.1
    cpe:2.3:a:php:php:5.3.1
  • Php » Php » Version: 5.3.2
    cpe:2.3:a:php:php:5.3.2
  • Php » Php » Version: 5.3.3
    cpe:2.3:a:php:php:5.3.3


Contact Us

Shodan ® - All rights reserved