QID 150542
Date Published: 2022-07-07
QID 150542: PHP Multiple Remote Code Execution Vulnerabilities (CVE-2022-31626,CVE-2022-31625)
PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications.
Affected versions of PHP has multiple vulnerabilities:
CVE-2022-31626 : mysqlnd/pdo password buffer overflow leading to RCE
CVE-2022-31625 : Uninitialized array in pg_query_params() leading to RCE
Affected Versions:
PHP versions 7.4.x prior to 7.4.30
PHP versions 8.0.x prior to 8.0.20
PHP versions 8.1.x prior to 8.1.7
QID Detection Logic (Unauthenticated):
This QID checks the HTTP Server header to see if the server is running a vulnerable version of PHP.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the target system.
For more information please refer to Sec Bug 81719 and Sec Bug 81720 .
- Sec Bug 81719 -
bugs.php.net/bug.php?id=81719 - Sec Bug 81720 -
bugs.php.net/bug.php?id=81720
CVEs related to QID 150542
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Sec Bug 81719 |
|
||
| Sec Bug 81720 |
|