Lucene search

K
prionPRIOn knowledge basePRION:CVE-2014-5120
HistoryAug 23, 2014 - 1:55 a.m.

Code injection

2014-08-2301:55:00
PRIOn knowledge base
www.prio-n.com
7

7.2 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.5%

gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.