PHP escapeshellarg Function Arbitrary Command Execution Vulnerability (CVE-2015-4642)
PHP escapeshellarg Function Arbitrary Command Execution Vulnerability (CVE-2015-4642)
Release date:
Updated on:
Affected Systems:
PHP <5.4.42
PHP 5.6.x <5.6.10
PHP 5.5.x <5.5.26
Description:
CVE (CAN) ID: CVE-2015-4642
PHP is a widely used scripting language. It is especially suitable for Web development and can be embedded into HTML.
In PHP <5.4.42, 5.5.x <5.5.26, 5.6.x <5.6.10, ext/standard/exec. c/escapeshellarg has a security vulnerability. Remote attackers can exploit this vulnerability to execute commands.
<* Source: PHP
*>
Suggestion:
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://php.net/ChangeLog-5.php
Http://php.net/ChangeLog-7.php
This article permanently updates the link address: