Published: 07/06/2016 Updated: 28/11/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Doctrine Annotations prior to 1.2.7, Cache prior to 1.3.2 and 1.4.x prior to 1.4.2, Common prior to 2.4.3 and 2.5.x prior to 2.5.1, ORM prior to 2.4.8 or 2.5.x prior to 2.5.1, MongoDB ODM prior to 1.0.2, and MongoDB ODM Bundle prior to 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

zend zend-cache 2.5.1

zend zend-cache 2.5.0

zend zend-cache

zend zend-cache 2.5.2

debian debian linux 8.0

debian debian linux 7.0

doctrine-project object relational mapper 2.5.0

doctrine-project object relational mapper

doctrine-project doctrinemongodbbundle 3.0.0

zend zend framework

doctrine-project common

doctrine-project common 2.5.0

doctrine-project annotations

doctrine-project mongodb-odm

doctrine-project cache 1.4.1

doctrine-project cache 1.4.0

doctrine-project cache

zend zf-apigility-doctrine

Github Repositories

example-php-composer Example PHP repository containing fake data with vulnerable dependencies There is at least one vulnerability to be reported: ZF2015-07: Filesystem Permissions Issues in Multiple Components (CVE-2015-5723, frameworkzendcom/security/advisory/ZF2015-07) Composer should know about this: $ composer install [] $ composer outdated zendframework/zend