CVE: CVE-2008-0599

Export to Word

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

Threat-Mapped Scoring

Score: 1.8

Priority: P4 - Informational (Low)

EPSS

Score: 0.51567
Percentile: 0.97767

CVSS Scoring

CVSS v3.1 Score: 9.8

Severity: CRITICAL

Mapped CWE(s)

All CAPEC(s)

CAPEC(s) with Mapped TTPs

Mapped ATT&CK TTPs

Affected Products

← Back to Home