5.8
CVSSv2

CVE-2017-7272

Published: 27/03/2017 Updated: 26/02/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 4 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

PHP up to and including 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

Exploits

PHP version 712 suffers from an incorrect behavior with fsockopen ...