CVE-2008-1488

Alternative PHP Cache (APC) <3.0.16 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1488. PoCs published by dannyp.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the PECL Alternative PHP Cache (APC) extension (versions prior to 3.0.17). It leverages a stack-based overflow to execute arbitrary shellcode, providing reverse shells for Linux and FreeBSD systems.

Description

Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long filename.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dannyp · phpremotelinux
https://www.exploit-db.com/exploits/31540

This exploit targets a buffer overflow vulnerability in the PECL Alternative PHP Cache (APC) extension (versions prior to 3.0.17). It leverages a stack-based overflow to execute arbitrary shellcode, providing reverse shells for Linux and FreeBSD systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: PECL Alternative PHP Cache (APC) < 3.0.17
No auth needed
Prerequisites: PHP with APC extension (3.0.11-3.0.16) · Ability to execute PHP code on the target system · Knowledge of the target system's memory layout for return address calculation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00582.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29745
Various Sources x_refsource_misc
http://papasian.org/~dannyp/apcsmash.php.txt
Exploit x_refsource_confirm
http://pecl.php.net/bugs/bug.php?id=13415
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41420
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29509
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00548.html
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:082
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31082
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200804-07.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28457

Scores

EPSS 0.0781
EPSS Percentile 93.9%

Details

CWE
CWE-119
Status published
Products (8)
pecl-php/alternative_php_cache 3.0.11
pecl-php/alternative_php_cache 3.0.12
pecl-php/alternative_php_cache 3.0.12p1
pecl-php/alternative_php_cache 3.0.12p2
pecl-php/alternative_php_cache 3.0.13
pecl-php/alternative_php_cache 3.0.14
pecl-php/alternative_php_cache 3.0.15
pecl-php/alternative_php_cache 3.0.16
Published Mar 24, 2008
Tracked Since Feb 18, 2026