PT-2010-1171 · Php+1 · Php+1

CVE-2010-3870

·

Publicado

2010-11-12

·

Atualizado

2023-02-13

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.4
Description The issue arises from the utf8 decode function not properly handling non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data. This makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string. The vulnerability can be exploited to conduct XSS attacks.
Recommendations For PHP versions prior to 5.3.4, update to version 5.3.4 or later to resolve the issue. As a temporary workaround, consider implementing additional input validation and sanitization to minimize the risk of exploitation. Restrict the use of the utf8 decode function until a patch is applied.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02600
CVE-2010-3870
DSA-2195-1
RHSA-2010:0919
RHSA-2010_0919
RHSA-2011:0195
RHSA-2011_0195

Produtos afetados

Php
Red Hat