ISOMAN

CVE

CVE-2018-5712

An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.

Severity
MEDIUM
CVSS
6.1
Published
Modified

Linked Releases

References

  1. http://php.net/ChangeLog-5.php
  2. http://php.net/ChangeLog-7.php
  3. http://www.securityfocus.com/bid/102742
  4. http://www.securityfocus.com/bid/104020
  5. http://www.securitytracker.com/id/1040363
  6. https://access.redhat.com/errata/RHSA-2018:1296
  7. https://access.redhat.com/errata/RHSA-2019:2519
  8. https://bugs.php.net/bug.php?id=74782
  9. https://lists.debian.org/debian-lts-announce/2018/01/msg00025.html
  10. https://usn.ubuntu.com/3566-1/
  11. https://usn.ubuntu.com/3600-1/
  12. https://usn.ubuntu.com/3600-2/
  13. https://www.oracle.com/security-alerts/cpuapr2020.html
  14. http://php.net/ChangeLog-5.php
  15. http://php.net/ChangeLog-7.php
  16. http://www.securityfocus.com/bid/102742
  17. http://www.securityfocus.com/bid/104020
  18. http://www.securitytracker.com/id/1040363
  19. https://access.redhat.com/errata/RHSA-2018:1296
  20. https://access.redhat.com/errata/RHSA-2019:2519