PHP CVE-2018-10545 Security Bypass Vulnerability
BID:104022
CVE-2018-10545 |Info
PHP CVE-2018-10545 Security Bypass Vulnerability
| Bugtraq ID: | 104022 |
| Class: | Configuration Error |
| CVE: |
CVE-2018-10545 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2018 12:00AM |
| Updated: | Apr 29 2018 12:00AM |
| Credit: | jd at cpanel dot net |
| Vulnerable: |
PHP PHP 7.2.3 PHP PHP 7.2.2 PHP PHP 7.2.1 PHP PHP 7.2 PHP PHP 7.1.13 PHP PHP 7.1.12 PHP PHP 7.1.11 PHP PHP 7.1.1 PHP PHP 7.1 PHP PHP 7.0.27 PHP PHP 7.0.26 PHP PHP 7.0.25 PHP PHP 7.0.22 PHP PHP 7.0.21 PHP PHP 7.0.17 PHP PHP 7.0.16 PHP PHP 7.0.15 PHP PHP 7.0.14 PHP PHP 7.0.12 PHP PHP 7.0.5 PHP PHP 7.0.3 PHP PHP 7.0 PHP PHP 5.6.33 PHP PHP 5.6.32 PHP PHP 5.6.31 PHP PHP 5.6.30 PHP PHP 5.6.29 PHP PHP 5.6.27 PHP PHP 5.6.22 PHP PHP 5.6.21 PHP PHP 5.6.20 PHP PHP 5.6.19 PHP PHP 5.6.18 PHP PHP 5.6.17 PHP PHP 5.6.13 PHP PHP 5.6.12 PHP PHP 5.6.11 PHP PHP 5.6.5 PHP PHP 5.6.4 PHP PHP 5.6.1 PHP PHP 5.6 PHP PHP 7.1.14 PHP PHP 7.0.9 PHP PHP 7.0.8 PHP PHP 7.0.7 PHP PHP 7.0.6 PHP PHP 7.0.4 PHP PHP 7.0.2 PHP PHP 7.0.13 PHP PHP 7.0.11 PHP PHP 7.0.10 PHP PHP 7.0.1 PHP PHP 5.6.9 PHP PHP 5.6.8 PHP PHP 5.6.7 PHP PHP 5.6.6 PHP PHP 5.6.34 PHP PHP 5.6.3 PHP PHP 5.6.28 PHP PHP 5.6.26 PHP PHP 5.6.25 PHP PHP 5.6.24 PHP PHP 5.6.23 PHP PHP 5.6.2 PHP PHP 5.6.14 PHP PHP 5.6.10 |
| Not Vulnerable: |
PHP PHP 7.2.4 PHP PHP 7.1.16 PHP PHP 7.0.29 PHP PHP 5.6.35 |
Discussion
PHP CVE-2018-10545 Security Bypass Vulnerability
PHP is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and gain unauthorized access to the application.
PHP versions prior to 5.6.35, 7.0.x prior to 7.0.29, 7.1.x prior to 7.1.16, and 7.2.x prior to 7.2.4 are vulnerable.
PHP is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and gain unauthorized access to the application.
PHP versions prior to 5.6.35, 7.0.x prior to 7.0.29, 7.1.x prior to 7.1.16, and 7.2.x prior to 7.2.4 are vulnerable.
Exploit / POC
PHP CVE-2018-10545 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PHP CVE-2018-10545 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PHP CVE-2018-10545 Security Bypass Vulnerability
References:
References: