6.8
CVSSv2

CVE-2009-5016

Published: 12/11/2010 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP prior to 5.2.11 makes it easier for remote malicious users to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.0.0

php php 5.1.1

php php 5.1.2

php php

php php 4.0

php php 4.0.6

php php 4.0.7

php php 4.1.2

php php 4.3.0

php php 4.3.5

php php 4.3.6

php php 4.3.7

php php 4.4.4

php php 4.4.5

php php 3.0.13

php php 3.0.12

php php 3.0.14

php php 5.0.4

php php 5.0.5

php php 5.1.5

php php 5.1.6

php php 4.0.2

php php 4.0.3

php php 4.2.1

php php 4.2.2

php php 4.3.11

php php 4.3.2

php php 4.4.0

php php 4.4.1

php php 4.4.8

php php 4.4.9

php php 3.0.2

php php 3.0.18

php php 3.0.7

php php 3.0.8

php php 5.0.1

php php 5.0.2

php php 5.0.3

php php 5.1.3

php php 5.1.4

php php 4.0.0

php php 4.0.1

php php 4.2.0

php php 4.3.1

php php 4.3.10

php php 4.3.8

php php 4.3.9

php php 4.4.6

php php 4.4.7

php php 3.0.1

php php 3.0

php php 3.0.16

php php 3.0.9

php php 1.0

php php 3.0.17

php php 2.0b10

php php 2.0

php php 5.1.0

php php 5.2.0

php php 5.2.1

php php 4.0.4

php php 4.0.5

php php 4.1.0

php php 4.1.1

php php 4.2.3

php php 4.3.3

php php 4.3.4

php php 4.4.2

php php 4.4.3

php php 3.0.11

php php 3.0.10

php php 3.0.4

php php 3.0.3

php php 3.0.15

php php 3.0.5

php php 3.0.6

Vendor Advisories

It was discovered that an integer overflow in the XML UTF-8 decoding code could allow an attacker to bypass cross-site scripting (XSS) protections This issue only affected Ubuntu 606 LTS, Ubuntu 804 LTS, and Ubuntu 910 (CVE-2009-5016) ...