CVE-2018-5712
Public on 2018-01-16
Modified on 2024-02-02
Description
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 1 | php | No Fix Planned | ||
HAQM Linux 2 - Core | php | Pending Fix | ||
HAQM Linux 2 - Php8.2 Extra | php | Not Affected | ||
HAQM Linux 1 | php56 | 2018-02-07 | ALAS-2018-946 | Fixed |
HAQM Linux 1 | php70 | 2018-02-07 | ALAS-2018-946 | Fixed |
HAQM Linux 1 | php71 | 2018-02-07 | ALAS-2018-946 | Fixed |
HAQM Linux 2023 | php8.2 | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
NVD | CVSSv2 | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N |
NVD | CVSSv3 | 6.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |