vendor:
PHP
by:
rgod
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: PHP
Affected Version From: PHP version 4.4.6
Affected Version To: PHP version 4.4.6
Patch Exists: NO
Related CWE:
CPE: a:php:php:4.4.6
Platforms Tested:
2007
PHP 4.4.6 snmpget() object id local buffer overflow poc exploit
This is a proof of concept exploit for a buffer overflow vulnerability in the snmpget() function in PHP version 4.4.6. By sending a specially crafted SNMP request, an attacker can overwrite the EIP register and execute arbitrary code.
Mitigation:
Upgrade PHP version to a patched version that fixes the buffer overflow vulnerability.