CVE-2006-5465
HIGH severity · CVSS 7.5
7.5CVSS HIGH
Summary
Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)42%
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P
- http://docs.info.apple.com/article.html?artnum=304829
- http://issues.rpath.com/browse/RPL-761
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2006-0736.html
- http://secunia.com/advisories/22653
- http://secunia.com/advisories/22685
- http://secunia.com/advisories/22688