Published: 07/06/2016 Updated: 28/11/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Doctrine Annotations prior to 1.2.7, Cache prior to 1.3.2 and 1.4.x prior to 1.4.2, Common prior to 2.4.3 and 2.5.x prior to 2.5.1, ORM prior to 2.4.8 or 2.5.x prior to 2.5.1, MongoDB ODM prior to 1.0.2, and MongoDB ODM Bundle prior to 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

Vulnerable Product Search on Vulmon Subscribe to Product

zend zend-cache 2.5.1

zend zend-cache 2.5.0

zend zend-cache

zend zend-cache 2.5.2

debian debian linux 8.0

debian debian linux 7.0

doctrine-project object relational mapper 2.5.0

doctrine-project object relational mapper

doctrine-project doctrinemongodbbundle 3.0.0

zend zend framework

doctrine-project common

doctrine-project common 2.5.0

doctrine-project annotations

doctrine-project mongodb-odm

doctrine-project cache 1.4.1

doctrine-project cache 1.4.0

doctrine-project cache

zend zf-apigility-doctrine

Github Repositories

