CVE-2010-4156

Scottmac Libmbfl - Improper Input Validation

Title source: rule

Description

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).

Exploits (1)

exploitdb STUB VERIFIED
by Mateusz Kocielski · phpremotephp
https://www.exploit-db.com/exploits/34979

Scores

EPSS 0.1011
EPSS Percentile 93.1%

Details

CWE
CWE-20
Status published
Products (1)
scottmac/libmbfl 1.1.0
Published Nov 10, 2010
Tracked Since Feb 18, 2026