The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
References
Configurations
Information
Published : 2010-03-16 12:30
Updated : 2010-12-09 22:37
NVD link : CVE-2010-0397
Mitre link : CVE-2010-0397
JSON object : View
CWE
Products Affected
php
- php