PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
References
Configurations
Information
Published : 2000-12-18 21:00
Updated : 2018-05-02 18:29
NVD link : CVE-2000-0967
Mitre link : CVE-2000-0967
JSON object : View
CWE
Products Affected
php
- php