Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.
CVSS Information
N/A
Vulnerability Type
对外部实体的文件或目录可访问
Vulnerability Title
Facebook HHVM 信息泄露漏洞
Vulnerability Description
Facebook HHVM(又名HipHop Virtual Machine)是美国Facebook公司的一款能够显著提高PHP加载动态页面性能的虚拟机。 HHVM中存在安全漏洞。攻击者可利用该漏洞获取应用程序的直接访问权限,进而泄露信息。以下产品及版本受到影响:HHVM 4.3.0版本,4.4.0版本,4.5.0版本,4.6.0版本,4.7.0版本,4.8.0版本,3.30.5及之前版本,4.0版本,4.1版本,4.2版本。
CVSS Information
N/A
Vulnerability Type
N/A