5

CVE-2015-1352

Exploit

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.

Data is provided by the National Vulnerability Database (NVD)
ApplemacOS X Version <= 10.10.5
PhpPhp Version < 5.4.40
PhpPhp Version >= 5.5.0 < 5.5.24
PhpPhp Version >= 5.6.0 < 5.6.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 23.74% 0.958
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P