QID 150654

Date Published: 2023-03-03

QID 150654: PHP Denial of Service Vulnerability (CVE-2023-0662)

PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications.

In PHP, an excessive number of parts in an HTTP form upload can lead to a high consumption of server resources and an excessive number of log entries. This can result in a denial of service (DoS) attack on the server by exhausting CPU resources or disk space.

Affected Versions:
PHP Versions from 8.0.0 to 8.0.27
PHP Versions from 8.1.0 before 8.1.15
PHP Versions from 8.2.0 before 8.2.2

QID Detection Logic (Unauthenticated):
This QID checks the HTTP Server header to see if the server is running a vulnerable version of PHP.

Successful exploitation of the vulnerability can allow an attacker to trigger a Denial of Service attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade to the latest version of PHP.
    For more information please refer to Github Advisory .

    CVEs related to QID 150654

    Software Advisories
    Advisory ID Software Component Link
    Github Advisory URL Logo github.com/php/php-src/security/advisories/GHSA-54hq-v5wp-fqgv