PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
References
Configurations
History
No history.
Information
Published : 2000-12-19 05:00
Updated : 2018-05-03 01:29
NVD link : CVE-2000-0967
Mitre link : CVE-2000-0967
CVE.ORG link : CVE-2000-0967
JSON object : View
Products Affected
php
- php
CWE