PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 PHP的CGI组件中的sapi/cgi/cgi_main.c文件中存在安全漏洞,该漏洞源于程序使用mmap读取.php文件时,处理无效文件时没有正确验证映射的长度。远程攻击者可通过上传.php文件利用该漏洞获取php-cgi进程内存中的敏感信息;通过将有效的PHP脚本放置在与映射邻近的内存位置
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-9464 | Microweber CMS SQL注入漏洞 | |
| CVE-2010-5314 | Bedita 跨站脚本漏洞 | |
| CVE-2010-5315 | Bedita 跨站脚本漏洞 | |
| CVE-2010-5316 | SweetRice CMS 跨站脚本漏洞 | |
| CVE-2010-5317 | SweetRice CMS SQL注入漏洞 | |
| CVE-2010-5318 | SweetRice CMS 信任管理漏洞 | |
| CVE-2010-5319 | Kandidat CMS 跨站请求伪造漏洞 | |
| CVE-2010-5320 | MemHT Portal 跨站请求伪造漏洞 |
No comments yet