QID 150382
Date Published: 2021-11-02
QID 150382: PHP Multiple Vulnerabilities (CVE-2020-7071,CVE-2021-21702)
PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications.
Affected versions of PHP has multiple vulnerabilities such as "Null Dereference in SoapClient (CVE-2021-21702)" and "Improper validation of URL (CVE-2020-7071)"
Affected Versions:
PHP version from 8.0.0 to 8.0.1
PHP version from 7.3.0 to 7.3.26
PHP version from 7.4.0 to 7.4.14
Note: CVE-2020-7071 is fixed in PHP versions 7.4.14 and 8.0.1
QID Detection Logic (Unauthenticated):
This QID checks the HTTP Server header to see if the server is running a vulnerable version of PHP.
Successful exploitation of these vulnerabilities could allow an attacker to crash the PHP or bypass the URL filter to accept URL with invalid password as valid.
- PHP Bug #77423 -
bugs.php.net/bug.php?id=77423 - PHP Bug #80672 -
bugs.php.net/bug.php?id=80672
CVEs related to QID 150382
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PHP Download |
|