vendor:
PHP
by:
shinnai
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: PHP
Affected Version From: PHP <= 5.2.3
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Pro SP2
PHP <= 5.2.3 snmpget() object id local Buffer Overflow eip overwrite exploit
This exploit takes advantage of a buffer overflow vulnerability in the snmpget() function in PHP version 5.2.3 and earlier. It allows for an eip overwrite and can be used to execute arbitrary code.
Mitigation:
Upgrade to a patched version of PHP.