vendor:
PHP
by:
shinnai
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: PHP
Affected Version From: PHP 5.2.3
Affected Version To: PHP 5.2.3
Patch Exists: NO
Related CWE:
CPE: a:php:php:5.2.3
Platforms Tested:
2007
PHP 5.2.3 php_ntuser ntuser_getuserlist() Local Buffer Overflow
The exploit takes advantage of a buffer overflow vulnerability in the php_ntuser ntuser_getuserlist() function in PHP 5.2.3. By providing a specially crafted input, an attacker can overwrite the EIP register with arbitrary data, potentially allowing for remote code execution.
Mitigation:
Upgrade to a non-vulnerable version of PHP or apply relevant patches provided by the vendor.