CVE-2015-4148

Apple Mac OS X < 10.10.4 - Improper Input Validation

Title source: rule
STIX 2.1

Description

The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obtain sensitive information by providing crafted serialized data with an int data type, related to a "type confusion" issue.

Exploits (1)

exploitdb WORKING POC
by Filippo Roncari · pythonwebappsphp
https://www.exploit-db.com/exploits/38304

Scores

EPSS 0.1694
EPSS Percentile 95.0%

Details

CWE
CWE-20
Status published
Products (30)
apple/mac_os_x < 10.10.4
php/php 5.5.0 (13 CPE variants)
php/php 5.5.1
php/php 5.5.2
php/php 5.5.3
php/php 5.5.4
php/php 5.5.5
php/php 5.5.6
php/php 5.5.7
php/php 5.5.8
... and 20 more
Published Jun 09, 2015
Tracked Since Feb 18, 2026