5
CVSSv2

CVE-2011-0752

Published: 02/02/2011 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The extract function in PHP prior to 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent malicious users to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.2.1

php php 5.2.2

php php 5.2.9

php php 5.2.10

php php 5.1.1

php php 5.0.0

php php 5.0.4

php php 5.0.5

php php 4.0.6

php php 4.0.7

php php 4.0

php php 4.1.2

php php 4.3.0

php php 4.3.6

php php 4.3.7

php php 4.4.4

php php 4.4.5

php php 3.0.13

php php 3.0.12

php php 3.0.14

php php 3.0.17

php php 2.0b10

php php 2.0

php php 5.2.3

php php 5.2.4

php php 5.2.11

php php 5.2.12

php php 5.1.6

php php 5.1.4

php php 5.1.5

php php 4.0.0

php php 4.0.1

php php 4.2.0

php php 4.3.1

php php 4.3.10

php php 4.3.8

php php 4.3.9

php php 4.4.6

php php 4.4.7

php php 3.0.1

php php 3.0

php php 3.0.16

php php 3.0.9

php php 1.0

php php 5.2.0

php php 5.2.7

php php 5.2.8

php php 5.1.3

php php 5.1.2

php php 5.0.2

php php 5.0.3

php php 4.0.4

php php 4.0.5

php php 4.1.0

php php 4.1.1

php php 4.2.3

php php 4.3.3

php php 4.3.4

php php 4.3.5

php php 4.4.2

php php 4.4.3

php php 3.0.11

php php 3.0.10

php php 3.0.3

php php 3.0.15

php php 3.0.5

php php 3.0.6

php php 5.2.5

php php 5.2.6

php php 5.2.13

php php 5.1.0

php php

php php 5.0.1

php php 4.0.2

php php 4.0.3

php php 4.2.1

php php 4.2.2

php php 4.3.11

php php 4.3.2

php php 4.4.0

php php 4.4.1

php php 4.4.8

php php 4.4.9

php php 3.0.2

php php 3.0.18

php php 3.0.4

php php 3.0.7

php php 3.0.8