Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23981
HistoryApr 10, 2020 - 12:42 a.m.

Arbitrary Code Execution

2020-04-1000:42:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.018

Percentile

88.2%

php is vulnerable to arbitrary code execution. Multiple missing input sanitization flaws were discovered in PHP’s exif extension. A specially-crafted image file could cause the PHP interpreter to crash or, possibly, disclose portions of its memory when a PHP script tried to extract Exchangeable image file format (Exif) metadata from the image file.

References