在 Windows 系统上,PHP 的文件系统和流 API 未拒绝保留的设备名称(如 CON、PRN、AUX、NUL、COM1 到 COM9、LPT1 到 LPT9、CONIN$ 和 CONOUT$),当这些名称作为路径中的组成部分出现时,仍会被接受。因此,攻击者控制的文件名会直接传递至 CreateFileW() 函数,导致打开的是设备而非应用程序所预期的常规文件,这可能阻塞或挂起请求,并耗尽工作进程。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91765 | 7.5 HIGH | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node |
| CVE-2026-91767 | 6.5 MEDIUM | Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard |
| CVE-2026-91768 | 6.5 MEDIUM | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm |
| CVE-2025-14181 | 6.5 MEDIUM | Integer overflow to buffer overflow in soap HTTP parsing |
| CVE-2026-92842 | 5.9 MEDIUM | OOB read / info leak in convert.* stream filters when line-break-chars contains NUL |
| CVE-2026-91766 | 5.9 MEDIUM | Cross-origin credential leak in HTTP stream wrapper redirects |
| CVE-2026-93682 | 5.8 MEDIUM | Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca |
| CVE-2026-6103 | 4.3 MEDIUM | Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection |
| CVE-2026-91769 | 4.3 MEDIUM | TLS Hostname Verification Falls Back to CN After SAN Mismatch |
| CVE-2025-1218 | 3.4 LOW | Various packet overreads in mysqlnd_writeprotocol.c |
No comments yet