QID 38872

Date Published: 2022-06-15

QID 38872: Multiple Vulnerabilities in Hypertext Preprocessor (PHP)

PHP is a general purpose scripting language that is especially suited for web development and can be embedded into HTML. The PHP version prior to 8.1.7 running on the remote web server is affected by multiple vulnerabilities.

Affected Versions:
PHP versions 7.4.x prior to 7.4.30
PHP versions 8.0.x prior to 8.0.20
PHP versions 8.1.x prior to 8.1.7

QID Detection Logic
The qid checks the php version via banner.

Uninitialized array in pg_query_params() leading to RCE.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to PHP version 7.4.30, 8.0.20, 8.1.7 or later PHP.
    Vendor References

    CVEs related to QID 38872

    Software Advisories
    Advisory ID Software Component Link
    php download URL Logo www.php.net/downloads