CVE-2012-2688

EXPLOITED

PHP <5.3.15, <5.4.5 - Buffer Overflow

Title source: llm

Description

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

Exploits (2)

nomisec WORKING POC 5 stars
by shelld3v · remote
https://github.com/shelld3v/CVE-2012-2688
vulncheck_xdb WORKING POC
remote
https://github.com/Luth1er/CVE-2017-18345-COM_JOOMANAGER-ARBITRARY-FILE-DOWNLOAD

Scores

EPSS 0.3268
EPSS Percentile 96.9%

Details

VulnCheck KEV 2012-06-19
Status published
Products (46)
php/php 1.0
php/php 2.0
php/php 2.0b10
php/php 3.0
php/php 3.0.1
php/php 3.0.2
php/php 3.0.3
php/php 3.0.4
php/php 3.0.5
php/php 3.0.6
... and 36 more
Published Jul 20, 2012
Tracked Since Feb 18, 2026