CVE-2011-4885

Php < 5.3.8 - Improper Input Validation

Title source: rule

Description

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Christian Mehlmauer · pythondosphp
https://www.exploit-db.com/exploits/18305
exploitdb WORKING POC
by infodox · textdosphp
https://www.exploit-db.com/exploits/18296
exploitdb WORKING POC
phpwebappsphp
https://www.exploit-db.com/exploits/2012
metasploit WORKING POC
by Alexander Klink, Julian Waelde, Scott A. Crosby, Dan S. Wallach, Krzysztof Kotowicz, Christian Mehlmauer · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/hashcollision_dos.rb

References (27)

... and 7 more

Scores

EPSS 0.8657
EPSS Percentile 99.4%

Details

CWE
CWE-20
Status published
Products (38)
php/php 5.0.0 (8 CPE variants)
php/php 5.0.1
php/php 5.0.2
php/php 5.0.3
php/php 5.0.4
php/php 5.0.5
php/php 5.1.1
php/php 5.1.2
php/php 5.1.3
php/php 5.1.4
... and 28 more
Published Dec 30, 2011
Tracked Since Feb 18, 2026