CVE-2018-5712
Summary
| CVE | CVE-2018-5712 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-16 09:29:00 UTC |
| Updated | 2019-08-19 11:15:00 UTC |
| Description | An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3600-2: PHP vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3600-1: PHP vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| PHP CVE-2018-5712 Cross Site Scripting Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| PHP: PHP 7 ChangeLog |
CONFIRM |
php.net |
Release Notes, Vendor Advisory |
| PHP Input Validation Flaw in PHAR 404 Error Page Lets Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| USN-3566-1: PHP vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| PHP :: Sec Bug #74782 :: Reflected XSS in .phar 404 page |
CONFIRM |
bugs.php.net |
Issue Tracking, Patch, Vendor Advisory |
| [SECURITY] [DLA 1251-1] php5 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2020 |
N/A |
www.oracle.com |
|
| PHP: PHP 5 ChangeLog |
CONFIRM |
php.net |
Release Notes, Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| PHP CVE-2018-10547 Incomplete Fix Cross Site Scripting Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377294 Alibaba Cloud Linux Security Update for Hypertext Preprocessor (PHP) (ALINUX2-SA-2020:0054)
- 501131 Alpine Linux Security Update for php7