CVE-2006-0097

Php - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by mercenary · phplocalwindows
https://www.exploit-db.com/exploits/1406

Scores

EPSS 0.1224
EPSS Percentile 93.7%

Classification

CWE
CWE-119
Status draft

Affected Products (4)

php/php
php/php
php/php
php/php

Timeline

Published Jan 06, 2006
Tracked Since Feb 18, 2026