Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP ext/xml/xml.c文件xml_utf8_decode函数整数溢出漏洞
Vulnerability Description
PHP 是广泛使用的通用目的脚本语言,特别适合于Web开发,可嵌入到HTML中。 PHP 5.2.11之前版本中的ext/xml/xml.c文件中的xml_utf8_decode函数中存在整数溢出漏洞。远程攻击者更容易借助使用超长UTF-8编码的特制字符串绕过跨站脚本攻击以及SQL注入保护机制。
CVSS Information
N/A
Vulnerability Type
N/A