Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2000-0967

HIGH severity · CVSS 10
10CVSS HIGH

Summary

PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)21%

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products we track (1)

PHP

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: http://www.securityfocus.com/bid/1786 ↗