CVE-2010-4700 PUBLISHED CVSS 6.800000190734863 MEDIUM

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

EPSS 0.24% · 47.3th percentile

Risk Scores

CVSS v2.0
6.800000190734863
EPSS Score
0.24%
47.3th percentile

Affected Products

VendorProductVersions
n/an/an/a
phpphp5.3.2, 5.3.3

Timeline

References

Open in Interactive Console →