Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:14521
HistoryMay 02, 2019 - 4:52 a.m.

Remote Code Execution (RCE)

2019-05-0204:52:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.163 Low

EPSS

Percentile

96.0%

php is vulnerable to remote code execution. An integer signedness issue, leading to a heap-based buffer underflow, was found in the PHP scandir() function. If a remote attacker could upload an excessively large number of files to a directory the scandir() function runs on, it could cause the PHP interpreter to crash or, possibly, execute arbitrary code.

References