4.3
CVSSv2

CVE-2009-4142

Published: 21/12/2009 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The htmlspecialchars function in PHP prior to 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote malicious users to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.3.4

php php 4.3.3

php php 4.2.3

php php 4.2.2

php php 5.0

php php 4.4.2

php php 4.4.3

php php 5.0.0

php php 2.0b10

php php 4.4.8

php php 2.0

php php 3.0.10

php php 3.0.13

php php 3.0.3

php php 3.0.15

php php 3.0.7

php php 3.0.8

php php 4.0

php php 4.3.2

php php 4.3.11

php php 4.2.1

php php 4.4.7

php php 4.4.0

php php 4.4.1

php php 5.0.3

php php 1.0

php php 3.0.11

php php 3.0.18

php php 3.0.4

php php 3.0.9

php php 4.0.0

php php 4.0.4

php php 4.0.7

php php 5.2.0

php php 5.1.6

php php 5.2.3

php php 5.2.4

php php 4.3.6

php php 4.3.5

php php 4.3.0

php php 4.3.7

php php 4.4.4

php php 5.1.0

php php 5.0.2

php php 4.4.9

php php 4.2

php php 3.0.12

php php 3.0.1

php php 3.0.14

php php 3.0.17

php php 3.0.5

php php 3.0.6

php php 4.0.2

php php 4.0.1

php php

php php 5.1.3

php php 5.1.1

php php 5.2.8

php php 5.2.9

php php 4.0.3

php php 5.1.5

php php 5.1.4

php php 5.2.5

php php 5.2.6

php php 4.3.10

php php 4.3.1

php php 4.2.0

php php 4.1.0

php php 4.4.5

php php 4.4.6

php php 4.3.8

php php 4.3.9

php php 5.0.5

php php 5.0.4

php php 5.0.1

php php 5

php php 4

php php 3.0

php php 3.0.2

php php 3.0.16

php php 4.0.6

php php 4.0.5

php php 4.1.2

php php 4.1.1

php php 5.2.10

php php 5.2.1

php php 5.2.2

Vendor Advisories

Synopsis Moderate: php security update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix several security issues are now available forRed Hat Enterprise Linux 3, 4, and 5This update has been rated as having moderate security impact by the RedHat Security Response Team ...
Maksymilian Arciemowicz discovered that PHP did not properly handle the ini_restore function An attacker could exploit this issue to obtain random memory contents or to cause the PHP server to crash, resulting in a denial of service (CVE-2009-2626) ...
Several remote vulnerabilities have been discovered in PHP 5, an hypertext preprocessor The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-4142 The htmlspecialchars function does not properly handle invalid multi-byte sequences CVE-2009-4143 Memory corruption via session interruption In th ...

Exploits

source: wwwsecurityfocuscom/bid/37389/info PHP is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may let the attacker steal cooki ...
source: wwwsecurityfocuscom/bid/37389/info PHP is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may let the attacker steal cookie- ...