QID 38840

Date Published: 2021-05-19

QID 38840: PHP Denial Of Service Vulnerability

PHP is a general purpose scripting language that is especially suited for web development and can be embedded into HTML.

Affected Versions:
PHP 8.0 prior to version 8.0.2
PHP 7.3 prior to version 7.3.27
PHP 7.4 prior to version 7.4.15

QID Detection Logic
The qid checks the php version via banner.

Successful exploitation of these vulnerabilities could allow an attacker to cause a crash.P>

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to the latest version PHP 7.3.27, PHP 7.4.15, PHP 8.0.2.
    Vendor References

    CVEs related to QID 38840

    Software Advisories
    Advisory ID Software Component Link
    PHP 7.3.27 URL Logo www.php.net/ChangeLog-7.php#7.3.27
    PHP 7.4.15 URL Logo www.php.net/ChangeLog-7.php#7.4.15
    PHP 8.0.2 URL Logo www.php.net/ChangeLog-8.php#8.0.2