Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP is_a函数任意代码执行漏洞
Vulnerability Description
PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 PHP 5.3.7和5.3.8版本中存在漏洞。由于is_a函数触发__autoload函数调用,远程攻击者可通过提供特制URL,以及可能利用在某些PEAR数据包和客户自动加载程序中的不安全行为执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A