Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-0752

EPSS 0.54% · P68
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-0752

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
PHP extract功能输入验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHP 是一款免费开放源代码的WEB脚本语言包,可使用在Microsoft Windows、Linux和Unix操作系统下。 PHP 5.2.15之前版本中的extract功能不能阻止使用EXTR_OVERWRITE参数去重写(1)GLOBALS superglobal数组和(2)this变量。上下文相关攻击者可以通过修改无意依赖外部输入的数据结构绕过预设的访问限制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-0752

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-0752

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-02-02 · 25 CVEs total

CVE-2010-3854Apache CouchDB Web管理界面多个跨站脚本攻击漏洞
CVE-2011-0742Novell ZENworks Handheld Management ZfHIPCnd.exe缓冲区溢出漏洞
CVE-2011-0741MODx Evolution多个跨站脚本攻击漏洞
CVE-2011-0740Pleer RSS Feed Reader magpie/scripts/magpie_slashbox.php跨站脚本攻击漏洞
CVE-2011-0739Ruby Mail gem deliver功能任意Shell命令执行漏洞
CVE-2011-0738Globus MyProxy证书验证安全绕过漏洞
CVE-2011-0276HP OpenView Performance Insight Server远程任意代码执行漏洞
CVE-2011-0017Exim 'log.c'程序本地权限提升漏洞
CVE-2010-4652ProFTPD mod_sql模块远程堆缓冲区溢出漏洞
CVE-2010-4015PostgreSQL intarray数组模块gettoken()函数缓冲区溢出漏洞
CVE-2010-3930MODx Evolution目录遍历漏洞
CVE-2010-3929MODx Evolution AjaxSearch SQL注入漏洞
CVE-2010-3041Cisco WebEx WRF和ARF文件格式处理多个缓冲区溢出漏洞
CVE-2010-3719Symantec IM Manager IMAdminSchedTask.asp文件eval注入漏洞
CVE-2011-0755PHP mt_rand函数整数溢出漏洞
CVE-2011-0754PHP Standard PHP Library扩展SplFileInfo::getType函数后置链接漏洞
CVE-2011-0753PHP PCNTL扩展拒绝服务漏洞
CVE-2011-0757IBM DB2 DBADM权限撤销非DDL声明执行漏洞
CVE-2011-0521Linux Kernel 'dvb_ca_ioctl()'内存破坏漏洞
CVE-2010-3270Cisco WebEx ATP文件栈缓冲区溢出漏洞

Showing top 20 of 25 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2011-0752

No comments yet


Leave a comment