Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP shmop函数 任意代码执行漏洞
Vulnerability Description
PHP 4.4.5之前版本和5.1系列中5.2.1之前的版本中的shmop函数没有验证它们的自变量是否与shmop资源相对应,这使得见机行事的攻击者可以借助与不恰当的资源相连接的自变量,读取和重写任意的内存分配。比如GD图像源。
CVSS Information
N/A
Vulnerability Type
N/A