VDB
CVE-2010-2094
CVE-2010-2094
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the (1) phar_stream_flush, (2) phar_wrapper_unlink, (3) phar_parse_url, or (4) phar_wrapper_open_url functions in ext/phar/stream.c; and the (5) phar_wrapper_open_dir function in ext/phar/dirstream.c, which triggers errors in the php_stream_wrapper_log_error function.
EPSS 3.09% · 87.0th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
3.09%
87.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| php | php | 5.3.0, 5.3.1 |
Exploit Intelligence
- http://php-security.org/2010/05/14/mops-2010-024-php-phar_stream_flush-format-string-vulnerability/index.html (nist-nvd)
- http://php-security.org/2010/05/14/mops-2010-025-php-phar_wrapper_open_dir-format-string-vulnerability/index.html (nist-nvd)
- http://php-security.org/2010/05/14/mops-2010-026-php-phar_wrapper_unlink-format-string-vulnerability/index.html (nist-nvd)
- http://php-security.org/2010/05/14/mops-2010-027-php-phar_parse_url-format-string-vulnerabilities/index.html (nist-nvd)
- http://php-security.org/2010/05/14/mops-2010-028-php-phar_wrapper_open_url-format-string-vulnerabilities/index.html (nist-nvd)
- ADV-2011-0068 (circl)
- SUSE-SR:2010:017 (circl)
- MDVSA-2011:004 (circl)
- SUSE-SR:2010:018 (circl)
Timeline
- May 27, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 18, 2025 EPSS Score
- Mar 19, 2025 EPSS Score
- Mar 20, 2025 EPSS Score
- Mar 24, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- Apr 15, 2025 EPSS Score
- Apr 18, 2025 EPSS Score
- Apr 20, 2025 EPSS Score
References
- http://php-security.org/2010/05/14/mops-2010-028-php-phar_wrapper_open_url-format-string-vulnerabilities/index.html url
- http://php-security.org/2010/05/14/mops-2010-024-php-phar_stream_flush-format-string-vulnerability/index.html url
- ADV-2011-0068 vdb
- http://php-security.org/2010/05/14/mops-2010-027-php-phar_parse_url-format-string-vulnerabilities/index.html url
- http://php-security.org/2010/05/14/mops-2010-025-php-phar_wrapper_open_dir-format-string-vulnerability/index.html url
- SUSE-SR:2010:017 vendor-advisory
- MDVSA-2011:004 vendor-advisory
- SUSE-SR:2010:018 vendor-advisory
- http://php-security.org/2010/05/14/mops-2010-026-php-phar_wrapper_unlink-format-string-vulnerability/index.html url
- https://nvd.nist.gov/vuln/detail/CVE-2010-2094 advisory