10

CVE-2000-0967

Exploit
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version 3.0
Php ≫ Php Version 4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 20.63% 0.972
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2000-10/0204.html
http://www.atstake.com/research/advisories/2000/a101200-1.txt
http://www.securityfocus.com/bid/1786
Patch
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/5359
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:75.php.asc
http://www.calderasystems.com/support/security/advisories/CSSA-2000-037.0.txt
http://www.linux-mandrake.com/en/security/MDKSA-2000-062.php3?dis=7.1
http://www.redhat.com/support/errata/RHSA-2000-088.html
http://www.redhat.com/support/errata/RHSA-2000-095.html