Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP 5.2.6 'cgi_main.c' URI 安全漏洞
Vulnerability Description
PHP是广泛使用的通用目的脚本语言,特别适合于Web开发,可嵌入到HTML中。 PHP的5.2.6之前版本存在多个安全漏洞,允许恶意用户绕过安全限制、导致拒绝服务或入侵有漏洞的系统。 sapi/cgi/cgi_main.c中的init_request_info功能PATH_TRANSLATED长度计算不适当的优先操作,可使远程攻击者在URI执行任意代码.
CVSS Information
N/A
Vulnerability Type
N/A