CVE-2006-0097

Php - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by mercenary · phplocalwindows
https://www.exploit-db.com/exploits/1406

Scores

EPSS 0.1224
EPSS Percentile 93.9%

Details

CWE
CWE-119
Status published
Products (4)
php/php 4.3.10
php/php 4.4.0
php/php 4.4.1
php/php 4.4.2
Published Jan 06, 2006
Tracked Since Feb 18, 2026