VDB
CVE-2018-1000888
CVE-2018-1000888
PUBLISHED
EPSS 24.69% · 96.2th percentile
Risk Scores
EPSS Score
24.69%
96.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | php-pear |
Exploit Intelligence
- https://blog.ripstech.com/2018/new-php-exploitation-technique/ (nist-nvd)
- https://cdn2.hubspot.net/hubfs/3853213/us-18-Thomas-It%27s-A-PHP-Unserialization-Vulnerability-Jim-But-Not-As-We-....pdf (nist-nvd)
- https://www.exploit-db.com/exploits/46108/ (nist-nvd)
- PEAR Archive_Tar < 1.4.4 - PHP Object Injection Vulnerability (0day-today)
- PEAR Archive_Tar < 1.4.4 - PHP Object Injection Vulnerability (0day-today)
Timeline
- Dec 27, 2018 CVE Published
- Jan 10, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 13, 2023 EPSS Score
References
- ALAS2-2019-1159: php-pear (medium) advisory