Record summary

CVE-2012-3450 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.

Description

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPHP 5.4.3 - PDO Memory Access Violation Denial of ServiceExploitDB exploitby 0x721427D8Not analyzed1 file
ExploitDB

PoC details

References

11