Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23311
HistoryApr 10, 2020 - 12:22 a.m.

Arbitrary Code Execution

2020-04-1000:22:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.245

Percentile

96.7%

php is vulnerable to arbitrary code execution. A flaw was found in PHP’s CGI server API. If the web server did not set DOCUMENT_ROOT environment variable for PHP (e.g. when running PHP in the FastCGI server mode), an attacker could cause a crash of the PHP child process, causing a temporary denial of service.

References