CVE Vulnerabilities

CVE-2015-6527

Published: Jan 19, 2016 | Modified: Nov 07, 2023
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplace function.

Affected Software

Name Vendor Start Version End Version
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0
Php Php 7.0.0 7.0.0

References