Lucene search

K
cvelistMitreCVELIST:CVE-2015-4147
HistoryJun 09, 2015 - 6:00 p.m.

CVE-2015-4147

2015-06-0918:00:00
mitre
www.cve.org
1

8.8 High

AI Score

Confidence

High

0.133 Low

EPSS

Percentile

95.6%

The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary code by providing crafted serialized data with an unexpected data type, related to a “type confusion” issue.