7.2
CVSSv2

CVE-2015-5723

Published: 07/06/2016 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Doctrine Annotations prior to 1.2.7, Cache prior to 1.3.2 and 1.4.x prior to 1.4.2, Common prior to 2.4.3 and 2.5.x prior to 2.5.1, ORM prior to 2.4.8 or 2.5.x prior to 2.5.1, MongoDB ODM prior to 1.0.2, and MongoDB ODM Bundle prior to 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

Vulnerable Product Search on Vulmon Subscribe to Product

zend zend-cache 2.5.1

zend zend-cache 2.5.0

zend zend-cache 2.5.2

zend zend-cache

debian debian linux 8.0

debian debian linux 7.0

doctrine-project object relational mapper 2.5.0

doctrine-project object relational mapper

doctrine-project doctrinemongodbbundle 3.0.0

zend zend framework

doctrine-project common

doctrine-project common 2.5.0

doctrine-project annotations

doctrine-project mongodb-odm

doctrine-project cache 1.4.0

doctrine-project cache 1.4.1

doctrine-project cache

zend zf-apigility-doctrine

Github Repositories

example-php-composer Example PHP repository containing fake data with vulnerable dependencies There is at least one vulnerability to be reported: ZF2015-07: Filesystem Permissions Issues in Multiple Components (CVE-2015-5723, frameworkzendcom/security/advisory/ZF2015-07) Composer should know about this: $ composer install [] $ composer outdated zendframework/zend