10

CVE-2015-4642

Exploit
The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version <= 5.4.41
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.0
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.1
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.2
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.3
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.4
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.5
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.6
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.7
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.8
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.9
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.10
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.11
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.12
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.13
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.14
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.15
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.16
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.17
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.18
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.19
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.20
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.21
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.22
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.23
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.24
   Microsoft ≫ Windows
Php ≫ Php Version 5.5.25
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.0
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.1
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.2
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.3
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.4
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.5
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.6
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.7
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.8
   Microsoft ≫ Windows
Php ≫ Php Version 5.6.9
   Microsoft ≫ Windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

http://php.net/ChangeLog-5.php
https://security.gentoo.org/glsa/201606-10
http://www.securitytracker.com/id/1032709
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=d2ac264ffea5ca2e85640b6736e0c7cd4ee9a4a9
http://openwall.com/lists/oss-security/2015/06/18/6
http://www.securityfocus.com/bid/75290
https://bugs.php.net/bug.php?id=69646
Exploit