QID 38872
Date Published: 2022-06-15
QID 38872: Multiple Vulnerabilities in Hypertext Preprocessor (PHP)
PHP is a general purpose scripting language that is especially suited for web development and can be embedded into HTML. The PHP version prior to 8.1.7 running on the remote web server is affected by multiple vulnerabilities.
Affected Versions:
PHP versions 7.4.x prior to 7.4.30
PHP versions 8.0.x prior to 8.0.20
PHP versions 8.1.x prior to 8.1.7
QID Detection Logic
The qid checks the php version via banner.
Uninitialized array in pg_query_params() leading to RCE.
Solution
Customers are advised to upgrade to PHP version 7.4.30, 8.0.20, 8.1.7 or later PHP.
Vendor References
- PHP 8 Change log -
www.php.net/ChangeLog-8.php#8.1.7 - Uninitialized array in pg_query_params leading to RCE -
bugs.php.net/bug.php?id=81720 - mysqlnd/pdo password buffer overflow leading to RCE -
bugs.php.net/bug.php?id=81719
CVEs related to QID 38872
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| php download |
|